VYPR

rpm package

almalinux/udisks2-iscsi

pkg:rpm/almalinux/udisks2-iscsi

Vulnerabilities (5)

  • CVE-2026-7867HigAug 6, 2026
    affected < 2.11.0-2.el10_2.1.alma.2fixed 2.11.0-2.el10_2.1.alma.2

    A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting

  • CVE-2026-26104MedFeb 25, 2026
    affected < 2.10.90-6.el10_1.1.alma.1fixed 2.10.90-6.el10_1.1.alma.1

    A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a

  • CVE-2026-26103HigFeb 25, 2026
    affected < 2.10.90-6.el10_1.1.alma.1fixed 2.10.90-6.el10_1.1.alma.1

    A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption meta

  • CVE-2025-8067HigAug 28, 2025
    affected < 2.9.0-16.el8_10.1fixed 2.9.0-16.el8_10.1

    A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the

  • CVE-2021-3802MedNov 29, 2021
    affected < 2.9.0-9.el8fixed 2.9.0-9.el8

    A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.