Two vulnerabilities in Ubuntu-specific patches to AccountsService, CVE-2026-61897 and CVE-2026-61898, allow a local attacker to execute arbitrary commands, with one flaw permitting privilege escalation to administrator. The update provides fixes for Ubuntu 14.04 LTS, 16.04 LTS, 18.04 LTS, and 20.04 LTS, corresponding to the original USN-8580-1 advisory.
USN-8580-1 fixed vulnerabilities in AccountsService. This update provides the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898)