VYPR

Udev

by Systemd Project

CVEs (5)

  • CVE-2026-40225MedApr 10, 2026
    risk 0.35cvss 6.4epss 0.00

    In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

  • CVE-2009-1185Apr 17, 2009
    risk 0.10cvss epss 0.82

    udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

  • CVE-2011-0640Jan 25, 2011
    risk 0.00cvss epss 0.00

    The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data…

  • CVE-2010-4176Dec 7, 2010
    risk 0.00cvss epss 0.02

    plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.

  • CVE-2009-1186Apr 17, 2009
    risk 0.00cvss epss 0.01

    Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.