Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjgq-ff5j-5v2m

Опубликовано: 25 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.

EPSS

Процентиль: 2%
0.00011
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.

CVSS3: 5.5
redhat
4 месяца назад

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.

CVSS3: 5.5
nvd
4 месяца назад

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.

CVSS3: 5.5
debian
4 месяца назад

A flaw was found in the udisks storage management daemon that allows u ...

rocky
3 месяца назад

Important: udisks2 security update

EPSS

Процентиль: 2%
0.00011
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-862