在 Ubuntu 中,随 accountsservice(版本低于 23.13.9-8ubuntu7)一起发布的特定于 Ubuntu 的语言辅助脚本(save-to-pam-env、update-langlist)将 ~/.pam_environment 文件中由用户控制的 LANGUAGE 条目视为可信输入。该值未加转义地被插入到 GNU sed 的替换表达式中,攻击者可通过注入 sed 的 'e' 标志以及任意 shell 命令,从而以 AccountsService 辅助进程的权限(真实用户 ID 为 0)执
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Canonical | accountsservice | 22.07.5-2ubuntu1< 22.07.5-2ubuntu1.6 |
affected |
23.13.9-2ubuntu6< 23.13.9-2ubuntu6.1 |
affected | ||
23.13.9-8ubuntu5< 23.13.9-8ubuntu5.2 |
affected | ||
23.13.9-8ubuntu6< 23.13.9-8ubuntu7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Canonical | accountsservice | 22.07.5-2ubuntu1 ~ 22.07.5-2ubuntu1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61897 | 7.8 HIGH | accountsservice: incomplete privilege drop when running Ubuntu-specific language helper sc |
| CVE-2026-77113 | 6.7 MEDIUM | Path Traversal Vulnerability in apport-unpack |
No comments yet