PT-2024-27978 · Gnome+2 · Gnome Settings Daemon+2

Michael Fincham

·

Published

2024-06-15

·

Updated

2024-11-12

·

CVE-2024-38394

CVSS v3.1

4.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GNOME Settings Daemon versions through 46.0
Description Mismatches in interpreting USB authorization policy between GNOME Settings Daemon and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations.
Recommendations For GNOME Settings Daemon versions through 46.0, consider this issue as part of a new feature implementation rather than a vulnerability fix, as indicated by the GSD supplier. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Related Identifiers

CVE-2024-38394
OPENSUSE-SU-2024:14060-1
OPENSUSE-SU-2024_2168-1
OPENSUSE-SU-2024_2170-1
OPENSUSE-SU-2024_2186-1
SUSE-SU-2024:2168-1
SUSE-SU-2024:2170-1
SUSE-SU-2024:2186-1
SUSE-SU-2024_2168-1
SUSE-SU-2024_2170-1
SUSE-SU-2024_2186-1

Affected Products

Debian
Gnome Settings Daemon
Suse