Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3802

Опубликовано: 13 сент. 2021
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

Отчет

Mounting a file system is a privileged operation controlled by polkit, So without admin authentication, it's difficult to exploit. And as for the Unprivileged users with an active session(e.g. GNOME session) can be affected by the auto-mounted devices. Hence the Priority is changed to low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7udisks2Out of support scope
Red Hat Enterprise Linux 9udisks2Not affected
Red Hat Enterprise Linux 8udisks2FixedRHSA-2022:182010.05.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2003649udisks2: insecure defaults in user-accessible mount helpers allow for a DoS

EPSS

Процентиль: 7%
0.00032
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
больше 3 лет назад

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

CVSS3: 4.2
nvd
больше 3 лет назад

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

CVSS3: 4.2
debian
больше 3 лет назад

A vulnerability found in udisks2. This flaw allows an attacker to inpu ...

suse-cvrf
почти 3 года назад

Security update for udisks2

suse-cvrf
почти 3 года назад

Security update for udisks2

EPSS

Процентиль: 7%
0.00032
Низкий

4.5 Medium

CVSS3