CVE-2022-1804: Accountsservice incorrectly drops privileges
Published Mar 25, 2025
·Updated
accountsservice no longer drops permissions when writting .pamenvironment
Affected Software
4 affected componentsFixes available
AccountsService accountsservice
Canonical Accountsservice<22.07.5-2ubuntu1.3
Canonical Ubuntu Linux=22.04
debian/accountsservice
0.6.55-322.08.8-623.13.9-723.13.9-8
Event History
Mar 25, 2025
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 26, 2025
Data Sourced
via Ubuntu·06:14 PM
RemedyDescriptionSeverityAffected Software
Sep 7, 2025
Data Sourced
via Debian·06:17 PM
DescriptionAffected Software
Sep 11, 2025
Data Sourced
via Launchpad·06:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-1804?
CVE-2022-1804 is classified as a low severity vulnerability.
2
How do I fix CVE-2022-1804?
To mitigate CVE-2022-1804, update the accountsservice package to the latest version provided by your Linux distribution.
3
What systems are affected by CVE-2022-1804?
CVE-2022-1804 specifically impacts the accountsservice component in various Linux distributions.
4
What kind of vulnerability is CVE-2022-1804?
CVE-2022-1804 is a permissions related vulnerability that affects how .pam_environment is written.
5
Is CVE-2022-1804 being actively exploited?
As of now, there is no public indication that CVE-2022-1804 is being actively exploited in the wild.