vulnerability
Oracle Linux: CVE-2018-17336: ELSA-2019-2178: udisks2 security, bug fix, and enhancement update (MODERATE)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:N/C:P/I:P/A:P) | Sep 22, 2018 | Jul 21, 2020 | Dec 3, 2025 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
Sep 22, 2018
Added
Jul 21, 2020
Modified
Dec 3, 2025
Description
UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.
An uncontrolled format string vulnerability has been discovered in udisks when it mounts a filesystem with a malformed label. A local attacker may use this flaw to leak memory, make the udisks service crash, or cause other unspecified effects.
An uncontrolled format string vulnerability has been discovered in udisks when it mounts a filesystem with a malformed label. A local attacker may use this flaw to leak memory, make the udisks service crash, or cause other unspecified effects.
Solutions
oracle-linux-upgrade-libudisks2oracle-linux-upgrade-libudisks2-develoracle-linux-upgrade-udisks2oracle-linux-upgrade-udisks2-iscsioracle-linux-upgrade-udisks2-lsmoracle-linux-upgrade-udisks2-lvm2
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.