CVE-2026-61897: accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/accountsserviceto a version that resolves this vulnerability.Fixed in 22.08.8-6Fixed in 23.13.9-7Fixed in 23.13.9-8 - Upgrade
Upgrade
accountsserviceto a version that resolves this vulnerability.Fixed in 23.13.9-8ubuntu7 - Compensating control
Ensure helper scripts run with non-root privileges by preventing inheritance of ruid=0 (root) so the real UID cannot remain 0 when launching language helper scripts.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61897?
CVE-2026-61897 has been assigned a risk level of 2, indicating a low severity vulnerability.
What systems are affected by CVE-2026-61897?
The details on affected systems for CVE-2026-61897 are currently unspecified due to the entry's likely erroneous nature.
What potential impact does CVE-2026-61897 have on security?
As CVE-2026-61897 is likely erroneous, its potential impact on security is currently unclear.
How can I stay updated on CVE-2026-61897?
You can monitor updates about CVE-2026-61897 through official CVE databases and security advisories.
How do I mitigate CVE-2026-61897?
Due to the likely erroneous nature of CVE-2026-61897, specific mitigation steps are not currently provided.