Opened 7 months ago
Closed 7 months ago
#22864 closed enhancement (fixed)
udisks2-2.11.1
| Reported by: | Bruce Dubbs | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (9)
comment:1 by , 7 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 7 months ago
| Priority: | elevated → high |
|---|
CVE-2026-26103 is rated as High. The details: "The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss."
Note: Successful exploitation results in a denial-of-service condition through irreversible data loss.
CVE-2026-26104 is rated as Medium. "The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes."
comment:3 by , 7 months ago
| Milestone: | 13.1 → 13.0 |
|---|
comment:4 by , 7 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:7 by , 7 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:8 by , 7 months ago
| Status: | new → assigned |
|---|

This is a bugfix release, fixing ATA USB device detection regression, leaking systemd inhibitors and missing polkit checks (CVE-2026-26103, CVE-2026-26104).
Changes since 2.11.0:
Tomas Bzatek (8):
Vojtech Trefny (4):