CVE-2026-61898

NameCVE-2026-61898
DescriptionThe Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
accountsservice (PTS)bullseye0.6.55-3fixed
bookworm22.08.8-6fixed
trixie23.13.9-7fixed
forky, sid23.13.9-8fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
accountsservicesource(unstable)(not affected)

Notes

- accountsservice <not-affected> (Ubuntu-specific changes)
https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985

Search for package or bug name: Reporting problems