Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-38394

Опубликовано: 16 июн. 2024
Источник: debian
EPSS Низкий

Описание

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnome-settings-daemonunfixedpackage

Примечания

  • https://pulsesecurity.co.nz/advisories/usbguard-bypass

  • https://gitlab.gnome.org/GNOME/gnome-settings-daemon/-/issues/780

  • https://gitlab.gnome.org/GNOME/gnome-settings-daemon/-/issues/780#note_2047914

  • As per Gnome upstream, consideration of a mitigation for the issue within

  • gnome-settings-daemon would rather be a new feature but not a vulnerability

  • fixing. The CVE assignment is disputed upstream with this context.

EPSS

Процентиль: 9%
0.00034
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 1 года назад

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

CVSS3: 7.1
redhat
больше 1 года назад

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

CVSS3: 4.3
nvd
больше 1 года назад

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

suse-cvrf
больше 1 года назад

Security update for gnome-settings-daemon

suse-cvrf
больше 1 года назад

Security update for gnome-settings-daemon

EPSS

Процентиль: 9%
0.00034
Низкий