REDHAT-BUG-1632828: Medium severity Udisks Udisks vulnerability
UDisks 2.8.0 has a format string vulnerability in udiskslog in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.
Upstream issue:
https://github.com/storaged-project/udisks/issues/578
Upstream patch:
https://github.com/pothos/udisks/commit/e369a9b4b08e9373c814c05328b366c938284eb5
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1632828?
The severity of REDHAT-BUG-1632828 is rated as high due to the potential for sensitive information exposure and memory corruption.
How do I fix REDHAT-BUG-1632828?
To fix REDHAT-BUG-1632828, update to UDisks version 2.8.1 or later as it contains the necessary security patches.
What causes the vulnerability in REDHAT-BUG-1632828?
The vulnerability in REDHAT-BUG-1632828 is caused by a format string issue in the logging function which can be exploited by malformed filesystem labels.
Who is affected by REDHAT-BUG-1632828?
Users and systems running UDisks version 2.8.0 are affected by REDHAT-BUG-1632828.
What kind of attacks can REDHAT-BUG-1632828 lead to?
REDHAT-BUG-1632828 can lead to denial of service through memory corruption and potential sensitive data leakage.