Impact
An insufficient authorization check in the 'as-user' option of the org.freedesktop.UDisks2.Filesystem.Mount D‑Bus method allows a local attacker with an active console session to spoof the parameter. By specifying an arbitrary user, the attacker can mount filesystems on behalf of that user, including privileged accounts, and manipulate the resulting mount namespace. This escalation can be used to gain unauthorized access to protected data or to tamper with system configuration.
Affected Systems
The vulnerability affects the udisks2 package in Red Hat Enterprise Linux releases 7, 8, 9 and 10. The exact version range is not specified, but the issue exists in all releases that use the vulnerable udisks2 component until a fixed release is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS data is not available, so the current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack requires a local attacker with console access; no remote exploitation is documented. Because the flaw permits mounting on behalf of privileged users, the potential impact is significant once the attacker obtains relevant privileges.
OpenCVE Enrichment
Debian DSA