#22029 closed enhancement (fixed)

udisks2-2.10.2

Reported by: Joe Locash Owned by: Douglas R. Reno
Priority: high Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Fixes CVE-2025-8067. Severity is high.

The UDisks daemon contains an out-of-bounds (OOB) read vulnerability that can be triggered by an unprivileged user via system bus. Successful exploitation leads to a crash of the daemon process, or mapping of an internal file descriptor from the daemon process onto a loop device, likely resulting in local privilege escalation.

​https://github.com/storaged-project/udisks/security/advisories/GHSA-742q-gggc-473g

​https://www.cve.org/CVERecord?id=CVE-2025-8067

Change History (3)

comment:1 by Douglas R. Reno, 13 months ago

Milestone: 12.5 → 12.4
Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

Given the severity of the security vulnerabilities here and the significant danger to users with QtWebEngine and Udisks especially, I have been tasked with doing these updates.

I will be rebuilding all dependents of them and reporting back with the status of them after they are tested. For Qt, this includes rebuilding and retesting all of LXQt and KDE Plasma. I will be doing these in a branch for review first before they get merged in.

Libreoffice, while not security related, will be updated as well because of the critical crash fix. It also has a fix in there which allows for characters to be un-bolded/italicized after they have been bolded or italicized.

comment:2 by Douglas R. Reno, 13 months ago

Summary: udisks-2.10.2 → udisks2-2.10.2

comment:3 by Douglas R. Reno, 13 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 256dbd440fc5f494a4f5293405bec41528b8386a

SA-12.3-100 issued

Note: See TracTickets for help on using tickets.