Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-38394

Опубликовано: 16 июн. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.3

Описание

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

РелизСтатусПримечание
devel

not-affected

disputed
esm-infra/bionic

not-affected

disputed
esm-infra/focal

not-affected

disputed
esm-infra/xenial

not-affected

disputed
focal

not-affected

disputed
jammy

not-affected

disputed
mantic

ignored

end of life, was deferred [2024-07-18]
noble

not-affected

disputed
upstream

needs-triage

Показывать по

EPSS

Процентиль: 9%
0.00034
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
больше 1 года назад

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

CVSS3: 4.3
nvd
больше 1 года назад

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

CVSS3: 4.3
debian
больше 1 года назад

Mismatches in interpreting USB authorization policy between GNOME Sett ...

suse-cvrf
больше 1 года назад

Security update for gnome-settings-daemon

suse-cvrf
больше 1 года назад

Security update for gnome-settings-daemon

EPSS

Процентиль: 9%
0.00034
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2024-38394