EIP-2026-103772
PRE-CVEDeepin Linux 15 - 'lastore-daemon' Local Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103772. PoCs published by bcoles.
AI-analyzed exploit summary This exploit leverages a misconfigured D-Bus interface in Deepin Linux 15.5's lastore-daemon, allowing any user in the sudo group to install arbitrary packages without authentication. It crafts a malicious .deb package with a post-install script that creates a setuid root shell, then uses dbus-send to trigger installation via the vulnerable D-Bus method.
Description
Deepin Linux 15 - 'lastore-daemon' Local Privilege Escalation
Exploits (1)
This exploit leverages a misconfigured D-Bus interface in Deepin Linux 15.5's lastore-daemon, allowing any user in the sudo group to install arbitrary packages without authentication. It crafts a malicious .deb package with a post-install script that creates a setuid root shell, then uses dbus-send to trigger installation via the vulnerable D-Bus method.