Opened 13 months ago
Closed 13 months ago
#22029 closed enhancement (fixed)
udisks2-2.10.2
| Reported by: | Joe Locash | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Fixes CVE-2025-8067. Severity is high.
The UDisks daemon contains an out-of-bounds (OOB) read vulnerability that can be triggered by an unprivileged user via system bus. Successful exploitation leads to a crash of the daemon process, or mapping of an internal file descriptor from the daemon process onto a loop device, likely resulting in local privilege escalation.
https://github.com/storaged-project/udisks/security/advisories/GHSA-742q-gggc-473g
Change History (3)
comment:1 by , 13 months ago
| Milestone: | 12.5 → 12.4 |
|---|---|
| Owner: | changed from to |
| Status: | new → assigned |
comment:2 by , 13 months ago
| Summary: | udisks-2.10.2 → udisks2-2.10.2 |
|---|
comment:3 by , 13 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 256dbd440fc5f494a4f5293405bec41528b8386a
SA-12.3-100 issued
Note:
See TracTickets
for help on using tickets.

Given the severity of the security vulnerabilities here and the significant danger to users with QtWebEngine and Udisks especially, I have been tasked with doing these updates.
I will be rebuilding all dependents of them and reporting back with the status of them after they are tested. For Qt, this includes rebuilding and retesting all of LXQt and KDE Plasma. I will be doing these in a branch for review first before they get merged in.
Libreoffice, while not security related, will be updated as well because of the critical crash fix. It also has a fix in there which allows for characters to be un-bolded/italicized after they have been bolded or italicized.