Lucene search

K
mageiaGentoo FoundationMGASA-2021-0529
HistoryDec 02, 2021 - 7:49 p.m.

Updated udisks2/libblockdev packages fix security vulnerability

2021-12-0219:49:28
Gentoo Foundation
advisories.mageia.org
25
udisks2
libblockdev
security vulnerability
kernel panic
system availability

CVSS2

6.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:N/I:N/A:C

CVSS3

4.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.0%

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

OSVersionArchitecturePackageVersionFilename
Mageia8noarchudisks2< 2.9.4-1udisks2-2.9.4-1.mga8
Mageia8noarchlibblockdev< 2.26-1libblockdev-2.26-1.mga8

CVSS2

6.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:N/I:N/A:C

CVSS3

4.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.0%