Executive brief
Ubuntu's AccountsService is a system daemon that manages user accounts and settings, including language preferences via D-Bus. An attacker with a local user account can exploit unsafe handling of language settings to inject arbitrary shell commands that execute with root privileges (UID 0), gaining complete control over the system. This requires only access to the attacker's own user account and default system policies.
Technical details
This is a compound local privilege escalation affecting AccountsService language helper scripts. The vulnerability stems from two root causes: (1) incomplete privilege dropping—AccountsService retains real UID 0 when launching helper processes, only dropping effective UID; and (2) shell injection in sed commands—user-controlled LANGUAGE entries from ~/.pam_environment are interpolated unescaped into a GNU sed replacement expression without sanitization. An attacker writes a crafted LANGUAGE value containing a sed 'e' flag and shell payload (e.g., `de;sh</pwn/e;#`) into their own .pam_environment file, then invokes SetLanguage via D-Bus on a non-English language. The helper script reads this attacker-controlled value and embeds it directly in a sed command, which executes the injected shell code with real UID 0. The attack requires a local user account and a non-English language pack installed, but no elevated privileges or user interaction. Patches are available for all affected Ubuntu releases.
Affected products
- Canonical AccountsService before 23.13.9-8ubuntu7 (Ubuntu-specific patch)
Timeline
- 2026-06-23: disclosed: Reported by Deutsche Telekom Red Team
- 2026-07-21: advisory: Published by Canonical/Ubuntu security team
- 2026-08-20: patched