Opened 7 months ago

Closed 7 months ago

#22864 closed enhancement (fixed)

udisks2-2.11.1

Reported by: Bruce Dubbs Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (9)

comment:1 by Xi Ruoyao, 7 months ago

Priority: normal → elevated

This is a bugfix release, fixing ATA USB device detection regression, leaking systemd inhibitors and missing polkit checks (CVE-2026-26103, CVE-2026-26104).

Changes since 2.11.0:

Tomas Bzatek (8):

  • lvm2: Prevent a segfault on discarded probe output
  • udiskslinuxdevice: Fix ATA USB detection
  • udiskslinuxnvmecontroller: Fix sanitize job start
  • udiskslinuxpartition: Fix missing job completion in handle_set_name
  • udiskslinuxpartitiontable: Fix missing job completion on overlapping partition error
  • udiskslinuxmanagernvme: Fix UINT64 variant handling in fabrics extra options
  • udiskslinuxblock: Add missing polkit check for RestoreEncryptedHeader()
  • udiskslinuxencrypted: Add missing polkit check for HeaderBackup()

Vojtech Trefny (4):

  • docs: Update links to documentation on storaged.org
  • udiskslinuxmdraid: Fix getting bitmap location on latest kernels
  • udisksobjectinfo: Fix compiler warning with C23
  • tests: Do not mount the loop device for SetAutoclear test

comment:2 by Douglas R. Reno, 7 months ago

Priority: elevated → high

CVE-2026-26103 is rated as High. The details: "The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss."

Note: Successful exploitation results in a denial-of-service condition through irreversible data loss.

CVE-2026-26104 is rated as Medium. "The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes."

comment:3 by Bruce Dubbs, 7 months ago

Milestone: 13.1 → 13.0

comment:4 by Joe Locash, 7 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:5 by Joe Locash, 7 months ago

Fixed at 85fd669e29.

Leaving open for SA.

comment:6 by zeckma, 7 months ago

I'll handle the SA.

comment:7 by Bruce Dubbs, 7 months ago

Owner: changed from Joe Locash to zeckma
Status: assigned → new

comment:8 by zeckma, 7 months ago

Status: new → assigned

comment:9 by zeckma, 7 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-110 issued.

Note: See TracTickets for help on using tickets.