Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5989-1] udisks2 security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5989-1] udisks2 security update


Chronologisch Thread  
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5989-1] udisks2 security update
  • Date: Thu, 28 Aug 2025 18:51:23 +0000
  • Authentication-results: lists.piratenpartei.de; dkim=none; dmarc=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
  • List-archive: https://lists.debian.org/msgid-search/E1urhiV-001wYX-1t AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=q11qAUc20SAiKEjlEypREWAG0IwOAAzVJWX/nnH+qas=; b=qB xp2nnRRDIBa+gCNazLVt1ppySISZlPwoHBeMHgKsKCkwtOGZazO4j5JcGEhstUSU8RL/hJdNG7spN hHXFlWZWK7+LwvCVbn9ftAoPV4i2Q0v9v4WTDBa+uDSfriWldAYNspAnahDtv0qxP6pUJmWHMuGt7 ptUR6IHLHYvhbOl3TrW2ngOH//A6hjAts3npOs5kcT0KX0vLB51J7K4sXF/0+HJY6yoxIfI0tdDqe ilEMTz9nhd2yME264YRChplPgy1j2NMR1cfSBGDxnPaY8lr1WmcbWnNMIM2DNiJuhVYWeNKIo79Wk FDsgcYiNGRo4KQYnxawneM/M0Y9H7k8A==;
  • Old-return-path: <carnil AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Thu, 28 Aug 2025 18:51:47 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <cFTrElipgwM.A.dp4K.DVKsoB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5989-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 28, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : udisks2
CVE ID : CVE-2025-8067

Michael Imfeld discovered an out-of-bounds read vulnerability in
udisks2, a D-Bus service to access and manipulate storage devices, which
may result in denial of service (daemon process crash), or in mapping an
internal file descriptor from the daemon process onto a loop device,
resulting in local privilege escalation.

For the oldstable distribution (bookworm), this problem has been fixed
in version 2.9.4-4+deb12u2.

For the stable distribution (trixie), this problem has been fixed in
version 2.10.1-12.1+deb13u1.

We recommend that you upgrade your udisks2 packages.

For the detailed security status of udisks2 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/udisks2

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmiwpQhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QQVBAAgvsfupJs+u21UNce4L4TQLmAQxWJUzxLdB4u422Y895K7+E3lS2+o6MB
XSGzfQX+tSrnoHlBYItU+574OYenNTTLYG03AL4caLxvVlixf9jOrEVdkAOQSllM
Nh2G72JE9CJsQmhtxDVrQmfrMQGs3pXPZViY1+IZ83ADwpzsj9pFbhcMM7d2DbxP
2hGvFT2fs7Suu0xMWpMVr4Z+6nYvAil5OUrjgLSm95iJoY2IcblXqRlOdtk6x4r5
Tu0srPBQT8wHjracKZgnjYldBLHjWE0B74qo3083Om7gAuDiLlOM16m0mSLIR/J7
gA7AM1fR6ft+O/nUt/bt8fjhtTTWyieRFmzklc/MCir2+AXzDhCNjLR2WojURm56
Zig/WfRU8FNuVbBlrIxRzjjlCo0q7FVXddC5x38B1xx2yn3sQtlJGaDwY7AsSwW2
L+VEGfp0WCyYJi4+VgmoOqg1YNuUrTJExzGgoJhjZMNiC58DMBWCbqz325H9QjrX
kcOqbcc1heSTRJO4QgD0cQjbqFsZvKiI6UkxhC3PJDFa0oP0K7NFbDhztYS/2gUC
fW7nPkCQTZ+1DfkT5kZYM0znY9UF1s3MDS8tvzzbR5NXaJ4IuRiuhRu8TlVZMX4j
AT+UfOurB7eMZD9wpUHNbNLriNcqWDipwvgxic2VViCrvJXMuHI=
=nG5/
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5989-1] udisks2 security update, Salvatore Bonaccorso, 28.08.2025

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang