REDHAT-BUG-2506381: Medium severity accountsservice vulnerability
A flaw was found in accountsservice. The systemd-homed handler for the SetIconFile D-Bus method (userchangeiconfilehomedauthorizedcb) opens a caller-supplied path as root without the path validation and privilege drop used by the classic handler. A local user with a systemd-homed-managed account can cause accounts-daemon to read arbitrary files (for example /etc/shadow) and store their contents as the user avatar. This issue affects accountsservice versions with homed avatar support (approximately 25.34.76 through 26.13.3) and is fixed in 26.26.9 by reading avatar files as the calling user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
accountsserviceto a version that resolves this vulnerability.Fixed in 26.26.9
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2506381?
The severity of REDHAT-BUG-2506381 is medium, rated at 4.
How do I fix REDHAT-BUG-2506381?
To fix REDHAT-BUG-2506381, update the accountsservice package to a version that includes the patch for the vulnerability.
What are the implications of REDHAT-BUG-2506381?
The implications of REDHAT-BUG-2506381 include the risk of a local user gaining unauthorized access to files and potential privilege escalation.
Who is affected by REDHAT-BUG-2506381?
Local users with systemd-homed-managed accounts are affected by REDHAT-BUG-2506381.
What component of the software is impacted by REDHAT-BUG-2506381?
The component impacted by REDHAT-BUG-2506381 is the SetIconFile D-Bus method in the accountsservice software.