
Weaponized local privilege escalation exploit for CVE-2026-7867 in udisks2, using as-user mount spoofing to bypass PolicyKit and gain a root shell.
as-user Spoofing → Authorization Bypass → Root-context Mount → LPECVE-2026-7867 is a local privilege escalation vulnerability in udisks2 involving the Filesystem.Mount D-Bus method, the as-user option, fstab-managed mount flows, and flawed authorization handling.
This private repository contains the technical research notes and PoC scripts used to validate the issue in a controlled lab environment.
The vulnerability was discovered and reported by:
| Azizcan Daştan | azqzazq1 |
| Özlem Ozan | oz7oz7 |
The issue was assigned:
CVE-2026-7867
The vulnerability is caused by a flawed trust relationship between the real D-Bus caller UID and the computed/effective UID produced by the as-user mount option.
In vulnerable flows, an unprivileged local user can influence the mount execution path so that a filesystem mount is performed in a privileged/root context without the expected PolicyKit authorization behavior.
The core bug is not simply “user-controlled mount options.”
The real issue is:
udisks2fails to consistently distinguish the original caller identity from the computedas-useridentity during fstab mount authorization and execution.
| Field | Value |
|---|---|
| CVE | CVE-2026-7867 |
| Product | udisks2 |
| Component | Filesystem.Mount |
| Attack Type | Local Privilege Escalation |
| Primitive | as-user spoofing |
| Security Boundary | D-Bus caller identity → privileged mount execution |
| Authorization Layer | PolicyKit / fstab mount authorization |
| Vendor | Red Hat / udisks upstream |
| Status | Patch in progress / coordinated disclosure |
| Planned Fix Release | udisks 2.11.2 |
The vulnerable logic is associated with the fstab mount handling path inside udisks2, especially when the mount request involves:
Filesystem.Mount
as-user
x-udisks-auth
user
users
The relevant security-sensitive areas are:
D-Bus caller identity
↓
as-user option handling
↓
fstab authorization logic
↓
PolicyKit decision flow
↓
root-context mount execution
┌─────────────────────────────┐
│ Unprivileged Local User │
└──────────────┬──────────────┘
│
│ Filesystem.Mount
│ with as-user influence
▼
┌─────────────────────────────┐
│ udisks2 / udisksd │
│ privileged system daemon │
└──────────────┬──────────────┘
│
│ fstab logic evaluates
│ user/auth options
▼
┌─────────────────────────────┐
│ Authorization Gap │
│ mount_other_user not │
│ enforced in skipped path │
└──────────────┬──────────────┘
│
│ root-context branch reached
▼
┌─────────────────────────────┐
│ Filesystem Mounted │
│ without expected auth flow │
└──────────────┬──────────────┘
│
│ impact depends on mount flags
▼
┌─────────────────────────────┐
│ Local Privilege Escalation │
│ controlled lab validation │
└─────────────────────────────┘
The vulnerable behavior comes from an identity confusion bug.
The system has multiple identity concepts:
real D-Bus caller UID
computed as-user UID
effective mount UID
udisksd daemon privilege context
The vulnerable flow fails to enforce these identities consistently.
In particular:
mount_other_user can become true because as-user is usedx-udisks-auth, user, or users can affect the authorization pathmount_other_user check is not reliably enforced outside that blockThe result is a local privilege boundary bypass.
x-udisks-auth ProblemThe x-udisks-auth option is supposed to force an administrative PolicyKit authorization flow.
Expected behavior:
mount request
↓
attempt mount as caller
↓
permission/auth failure
↓
PolicyKit filesystem-fstab check
↓
admin approval
↓
mount as authorized privileged action
Vulnerable behavior:
mount request with as-user influence
↓
computed identity affects execution
↓
mount succeeds too early
↓
PolicyKit auth path is not reached as expected
↓
privileged mount state is achieved
This makes the security model around x-udisks-auth unreliable in the vulnerable path.
Expected model:
Unprivileged user
↓
D-Bus mount request
↓
PolicyKit / fstab authorization
↓
restricted mount behavior
Broken model:
Unprivileged user
↓
D-Bus mount request with as-user spoofing
↓
authorization logic mismatch
↓
root-context mount execution
The bug is especially serious because the affected service runs with elevated privileges.
Successful exploitation may allow a local unprivileged user to mount a filesystem through udisks2 in a root-context execution path without the expected authorization prompt.
Depending on the filesystem and mount flags, impact may include:
This is a local vulnerability.
Relevant conditions include:
| Condition | Required |
|---|---|
| Local user access | Yes |
Vulnerable udisks2 version | Yes |
as-user functionality present | Yes |
| Suitable fstab-managed mount target | Yes |
| Vulnerable authorization path | Yes |
| Remote access | No |