Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
91

Gentoo: UDisks High Risk Arbitrary Code Exec Vulnerability GLSA 202511-01

Multiple vulnerabilities have been discovered in UDisks, the worst of which can lead to execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202511-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: UDisks: Multiple Vulnerabilities Date: November 24, 2025 Bugs: #827863, #962126 ID: 202511-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in UDisks, the worst of which can lead to execution of arbitrary code. Background ========== UDisks provides a daemon, tools and libraries to access and manipulate disks, storage devices and technologies. Affected packages ================= Package Vulnerable Unaffected ------------- ------------ ------------ sys-fs/udisks < 2.10.2 > = 2.10.2 Description =========== Multiple vulnerabilities have been discovered in UDisks. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All UDisks users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-fs/udisks-2.10.2" References ========== [ 1 ] CVE-2021-3802 https://nvd.nist.gov/vuln/detail/CVE-2021-3802 [ 2 ] CVE-2025-8067 https://nvd.nist.gov/vuln/detail/CVE-2025-8067 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202511-01 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is ofutmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2025 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Multiple vulnerabilities in UDisks can lead to the execution of arbitrary code. Upgrade is essential to ensure security.. UDisks Security, Gentoo Updates, High Vulnerability Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 24, 2025 Critical Gentoo
203

Mageia 9: MGASA-2025-0188 critical: libblockdev local privilege escalation

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root . MGASA-2025-0188 - Updated udisks2 & libblockdev packages fix security vulnerabilities Publication date: 24 Jun 2025 URL: https://advisories.mageia.org/MGASA-2025-0188.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-6019 A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system. References: - https://bugs.mageia.org/show_bug.cgi?id=34380 - https://www.openwall.com/lists/oss-security/2025/06/17/4 - https://www.cve.org/CVERecord?id=CVE-2025-6019 SRPMS: - 9/core/udisks2-2.10.1-1.1.mga9 - 9/core/libblockdev-3.3.1-1.mga9 . Mageia 9 addresses a vital local privilege elevation vulnerability in udisks2 and libblockdev. Swift updates advised.. Mageia advisory, udisks2 patch, libblockdev fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 24, 2025 Critical Mageia
197

Debian 11: DLA-4221-1 critical: libblockdev local privilege escalation

The Qualys Threat Research Unit (TRU) discovered a local privilege escalation vulnerability in libblockdev, a library for manipulating block devices. An "allow_active" user can exploit this flaw via the . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4221-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz June 17, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libblockdev Version : 2.25-2+deb11u1 CVE ID : CVE-2025-6019 The Qualys Threat Research Unit (TRU) discovered a local privilege escalation vulnerability in libblockdev, a library for manipulating block devices. An "allow_active" user can exploit this flaw via the udisks daemon to obtain the full privileges of the root user. Details can be found in the Qualys advisory at https://cdn2.qualys.com/2025/06/17/suse15-pam-udisks-lpe.txt Along with the libblockdev update, updated udisks2 packages are released, to enforce that private mounts are mounted with 'nodev,nosuid'. For Debian 11 bullseye, this problem has been fixed in version 2.25-2+deb11u1. We recommend that you upgrade your libblockdev packages. For the detailed security status of libblockdev please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libblockdev Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An urgent vulnerability in libblockdev on Debian needs immediate action to protect the security of the system.. local privilege escalation, Debian security, libblockdev update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 17, 2025 Critical Debian LTS
172

Ubuntu 18.04 LTS USN-3772-1 Critical Udisks Denial of Service Risk

Udisks could be made to crash or expose sensitive information.. =========================================================================Ubuntu Security Notice USN-3772-1 September 26, 2018 udisks2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Udisks could be made to crash or expose sensitive information. Software Description: - udisks2: service to access and manipulate storage devices Details: It was discovered that UDisks incorrectly handled format strings when logging. A local attacker could possibly use this issue to cause a denial of service or obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: udisks2 2.7.6-3ubuntu0.2 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3772-1 CVE-2018-17336 Package Information: https://launchpad.net/ubuntu/+source/udisks2/2.7.6-3ubuntu0.2 . A flaw in Udisks could result in system instability or unauthorized access to confidential information on Ubuntu 18.04 LTS. Immediate update is advised.. Udisks,Ubuntu Security,Denial of Service,Sensitive Data Exposure. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 26, 2018 Critical Ubuntu
98

CentOS 7: CSSA-2015:0454-01 Critical: Udisks Memory Leak

Updated udisks packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS). -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: udisks security update Advisory ID: RHSA-2014:0293-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:0293.html Issue date: 2014-03-13 CVE Names: CVE-2014-0004 ==================================================================== 1. Summary: Updated udisks packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, noarch, x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, noarch, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, noarch, x86_64 3. Description: The udisks package provides a daemon, a D-Bus API, and command line utilities for managing disks and storage devices. A stack-based buffer overflow flaw was found in the way udisks handled files with long path names. A malicious, local user could use this flaw to create a specially crafted directory structure that, when processed by the udisks daemon, could lead to arbitrary code execution withthe privileges of the udisks daemon (root). (CVE-2014-0004) This issue was discovered by Florian Weimer of the Red Hat Product Security Team. All udisks users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1049703 - CVE-2014-0004 udisks and udisks2: stack-based buffer overflow when handling long path names 1074964 - multilib conflicts for udisks-devel 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: udisks-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm x86_64: udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm noarch: udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm x86_64: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: noarch: udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm x86_64: udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: udisks-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm ppc64: udisks-1.0.1-7.el6_5.ppc64.rpm udisks-debuginfo-1.0.1-7.el6_5.ppc64.rpm s390x: udisks-1.0.1-7.el6_5.s390x.rpm udisks-debuginfo-1.0.1-7.el6_5.s390x.rpm x86_64: udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm Red HatEnterprise Linux Server Optional (v. 6): Source: i386: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm noarch: udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm ppc64: udisks-debuginfo-1.0.1-7.el6_5.ppc.rpm udisks-debuginfo-1.0.1-7.el6_5.ppc64.rpm udisks-devel-1.0.1-7.el6_5.ppc.rpm udisks-devel-1.0.1-7.el6_5.ppc64.rpm s390x: udisks-debuginfo-1.0.1-7.el6_5.s390.rpm udisks-debuginfo-1.0.1-7.el6_5.s390x.rpm udisks-devel-1.0.1-7.el6_5.s390.rpm udisks-devel-1.0.1-7.el6_5.s390x.rpm x86_64: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: udisks-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm x86_64: udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm noarch: udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm x86_64: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0004 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFTIgfaXlSAg2UNWIIRAu2jAJ9eS0/gyawi+yuD5dNe0vjBDvp4awCcCztm 09zBIa5MnfTy92sWT3BeND0=jUCJ -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch for udisks tackles critical vulnerability on Red Hat6; users advised to implement it without delay.. Red Hat, Udisks Update, Buffer Overflow Issue, Security Impact. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 13, 2014 Important Red Hat
200

Scientific Linux: SLSA-2014:0293-1 Important: Udisks Buffer Overflow Risk

Important: udisks security update. Date: Thu, 13 Mar 2014 20:10:37 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: udisks on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: udisks security update Advisory ID: SLSA-2014:0293-1 Issue Date: 2014-03-13 CVE Numbers: CVE-2014-0004 -- A stack-based buffer overflow flaw was found in the way udisks handled files with long path names. A malicious, local user could use this flaw to create a specially crafted directory structure that, when processed by the udisks daemon, could lead to arbitrary code execution with the privileges of the udisks daemon (root). (CVE-2014-0004) -- SL6 x86_64 udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm i386 udisks-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm noarch udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm - Scientific Linux Development Team . Urgent patch for udisks on Scientific Linux addresses a serious buffer overflow vulnerability, potentially enabling unauthorized code execution.. Scientific Linux Udisks Security Update, Stack Overflow Risk, Arbitrary Code Execution. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 13, 2014 Important Scientific Linux
98

Red Hat: RHSA-2014:0293-01 Important: Udisks Buffer Overflow Risk

Updated udisks packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: udisks security update Advisory ID: RHSA-2014:0293-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:0293.html Issue date: 2014-03-13 CVE Names: CVE-2014-0004 ==================================================================== 1. Summary: Updated udisks packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, noarch, x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, noarch, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, noarch, x86_64 3. Description: The udisks package provides a daemon, a D-Bus API, and command line utilities for managing disks and storage devices. A stack-based buffer overflow flaw was found in the way udisks handled files with long path names. A malicious, local user could use this flaw to create a specially crafted directory structure that, when processed by the udisks daemon, could lead to arbitrary code execution with the privileges of the udisks daemon (root). (CVE-2014-0004) This issue was discovered by Florian Weimer ofthe Red Hat Product Security Team. All udisks users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1049703 - CVE-2014-0004 udisks and udisks2: stack-based buffer overflow when handling long path names 1074964 - multilib conflicts for udisks-devel 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: udisks-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm x86_64: udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm noarch: udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm x86_64: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: noarch: udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm x86_64: udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: udisks-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm ppc64: udisks-1.0.1-7.el6_5.ppc64.rpm udisks-debuginfo-1.0.1-7.el6_5.ppc64.rpm s390x: udisks-1.0.1-7.el6_5.s390x.rpm udisks-debuginfo-1.0.1-7.el6_5.s390x.rpm x86_64: udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): Source: i386: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm noarch: udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm ppc64: udisks-debuginfo-1.0.1-7.el6_5.ppc.rpm udisks-debuginfo-1.0.1-7.el6_5.ppc64.rpm udisks-devel-1.0.1-7.el6_5.ppc.rpm udisks-devel-1.0.1-7.el6_5.ppc64.rpm s390x: udisks-debuginfo-1.0.1-7.el6_5.s390.rpm udisks-debuginfo-1.0.1-7.el6_5.s390x.rpm udisks-devel-1.0.1-7.el6_5.s390.rpm udisks-devel-1.0.1-7.el6_5.s390x.rpm x86_64: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: udisks-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.i686.rpm x86_64: udisks-1.0.1-7.el6_5.x86_64.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm noarch: udisks-devel-docs-1.0.1-7.el6_5.noarch.rpm x86_64: udisks-debuginfo-1.0.1-7.el6_5.i686.rpm udisks-debuginfo-1.0.1-7.el6_5.x86_64.rpm udisks-devel-1.0.1-7.el6_5.i686.rpm udisks-devel-1.0.1-7.el6_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0004 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . Security Bulletin for udisks: Critical patch addresses a memory corruption vulnerability. Prompt implementation is recommended for Fedora environments.. Red Hat Update, Udisks Security, Important Patch, Buffer Overflow Rescue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 13, 2014 Important Red Hat
99

Slackware: 2014-070-01 Critical: Udisks Buffer Overflow Threat

New udisks and udisks2 packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] udisks, udisks2 (SSA:2014-070-01) New udisks and udisks2 packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/udisks-1.0.5-i486-1_slack14.1.txz: Upgraded. This update fixes a stack-based buffer overflow when handling long path names. A malicious, local user could use this flaw to create a specially-crafted directory structure that could lead to arbitrary code execution with the privileges of the udisks daemon (root). For more information, see: https://www.cve.org/CVERecord?id=CVE-2014-0004 (* Security fix *) patches/packages/udisks2-2.1.3-i486-1_slack14.1.txz: Upgraded. This update fixes a stack-based buffer overflow when handling long path names. A malicious, local user could use this flaw to create a specially-crafted directory structure that could lead to arbitrary code execution with the privileges of the udisks daemon (root). For more information, see: https://www.cve.org/CVERecord?id=CVE-2014-0004 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated packages for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/udisks-1.0.5-i486-1_slack14.0.txz Updated packages for Slackware x86_6414.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/udisks-1.0.5-x86_64-1_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/udisks2-1.98.0-x86_64-2_slack14.0.txz Updated packages for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/udisks-1.0.5-i486-1_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/udisks2-2.1.3-i486-1_slack14.1.txz Updated packages for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/udisks-1.0.5-x86_64-1_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/udisks2-2.1.3-x86_64-1_slack14.1.txz Updated packages for Slackware -current: Updated packages for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 packages: d9c13285062b6707bb6ec5d44429a2b7 udisks-1.0.5-i486-1_slack14.0.txz 1c514a0f4c418536a75b2244204350b7 udisks2-1.98.0-i486-2_slack14.0.txz Slackware x86_64 14.0 packages: 643ca75f399529b87f56c0a9a3913071 udisks-1.0.5-x86_64-1_slack14.0.txz 0e8515b54e7ef316e003342d958cfccf udisks2-1.98.0-x86_64-2_slack14.0.txz Slackware 14.1 packages: b22178b1ef196e44b69032bcea6920a8 udisks-1.0.5-i486-1_slack14.1.txz 01547b6e7f73bbeb791b514d7b736e21 udisks2-2.1.3-i486-1_slack14.1.txz Slackware x86_64 14.1 packages: 688613c7d1c99e4f549e6c406166157b udisks-1.0.5-x86_64-1_slack14.1.txz 577cfd72cce040a7877312ca3a9f36b7 udisks2-2.1.3-x86_64-1_slack14.1.txz Slackware -current packages: 2dfd6acac20c52b701aa1e84a33d78aa a/udisks-1.0.5-i486-1.txz dc263cf4562f307fe37c0e1111a6f0a5 a/udisks2-2.1.3-i486-1.txz Slackware x86_64 -current packages: 062a0a820d7c85e6f5e407b6c5c3af82 a/udisks-1.0.5-x86_64-1.txz 14d403c4f6bea0afb57f3d6c15532b86 a/udisks2-2.1.3-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg udisks-1.0.5-i486-1_slack14.1.txz udisks2-2.1.3-i486-1_slack14.1.txz +-----+ . Updated udisksand udisks2 packages for Slackware have been released to address a significant buffer overflow vulnerability impacting system security.. Slackware Packages, Udisks Update, Security Fix, Buffer Overflow, Udisks2. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 11, 2014 Critical Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here