PT-2024-27978 · Gnome+2 · Gnome Settings Daemon+2
Michael Fincham
·
Published
2024-06-15
·
Updated
2024-11-12
·
CVE-2024-38394
CVSS v3.1
4.3
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
GNOME Settings Daemon versions through 46.0
Description
Mismatches in interpreting USB authorization policy between GNOME Settings Daemon and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations.
Recommendations
For GNOME Settings Daemon versions through 46.0, consider this issue as part of a new feature implementation rather than a vulnerability fix, as indicated by the GSD supplier. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Gnome Settings Daemon
Suse