EIP-2026-103772

PRE-CVE

Deepin Linux 15 - 'lastore-daemon' Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103772. PoCs published by bcoles.

AI-analyzed exploit summary This exploit leverages a misconfigured D-Bus interface in Deepin Linux 15.5's lastore-daemon, allowing any user in the sudo group to install arbitrary packages without authentication. It crafts a malicious .deb package with a post-install script that creates a setuid root shell, then uses dbus-send to trigger installation via the vulnerable D-Bus method.

Description

Deepin Linux 15 - 'lastore-daemon' Local Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by bcoles · bashlocalmultiple
https://www.exploit-db.com/exploits/47175

This exploit leverages a misconfigured D-Bus interface in Deepin Linux 15.5's lastore-daemon, allowing any user in the sudo group to install arbitrary packages without authentication. It crafts a malicious .deb package with a post-install script that creates a setuid root shell, then uses dbus-send to trigger installation via the vulnerable D-Bus method.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Deepin Linux 15.5 lastore-daemon
No auth needed
Prerequisites: User must be in the sudo group (default for first user) · dpkg-deb must be available · D-Bus access to lastore-daemon
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026