cbcvebase.

Debian Udisks2 vulnerabilities

6 known vulnerabilities affecting debian/udisks2.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2LOW2

Vulnerabilities

Page 1 of 1
CVE-2025-8067P3HIGHCVSS 8.5fixed in udisks2 2.9.4-4+deb12u2 (bookworm)2025
CVE-2025-8067 [HIGH] CVE-2025-8067: udisks2 - A flaw was found in the Udisks daemon, where it allows unprivileged users to cre... A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the file descriptor list and index specifying the file where the loop device should be backed
debian
CVE-2018-17336P4HIGHCVSS 7.8fixed in udisks2 2.8.1-1 (bookworm)2018
CVE-2018-17336 [HIGH] CVE-2018-17336: udisks2 - UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c,... UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings. Scope: local bookworm: resolved (fixed in 2.8.1-1) bull
debian
CVE-2026-26103P4LOWCVSS 7.1fixed in udisks2 2.11.1-1 (forky)2026
CVE-2026-26103 [HIGH] CVE-2026-26103: udisks2 - A flaw was found in the udisks storage management daemon that exposes a privileg... A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encryp
debian
CVE-2014-0004P4MEDIUMCVSS 6.9fixed in udisks2 2.1.3-1 (bookworm)2014
CVE-2014-0004 [MEDIUM] CVE-2014-0004: udisks2 - Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows l... Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point. Scope: local bookworm: resolved (fixed in 2.1.3-1) bullseye: resolved (fixed in 2.1.3-1) forky: resolved (fixed in 2.1.3-1) sid: resolved (fixed in 2.1.3-1) trixie: resolved (fixed
debian
CVE-2026-26104P4LOWCVSS 5.5fixed in udisks2 2.11.1-1 (forky)2026
CVE-2026-26104 [MEDIUM] CVE-2026-26104: udisks2 - A flaw was found in the udisks storage management daemon that allows unprivilege... A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controll
debian
CVE-2021-3802P4MEDIUMCVSS 4.2fixed in udisks2 2.9.4-1 (bookworm)2021
CVE-2021-3802 [MEDIUM] CVE-2021-3802: udisks2 - A vulnerability found in udisks2. This flaw allows an attacker to input a specia... A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.9.4-1) bullseye: resolved (fixed in 2.9.2-2+deb11u1) forky: resolved (fixed in 2.9.4-1) sid: resolved (fixed in 2.9.4-1) t
debian
Debian Udisks2 vulnerabilities | cvebase