SB2026073115 - Multiple vulnerabilities in fwupd



SB2026073115 - Multiple vulnerabilities in fwupd

Published: July 31, 2026

Security Bulletin ID SB2026073115
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Improper Authorization (CVE-ID: N/A)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to install a downgrade as a trusted update without a prompt.

The vulnerability exists due to improper access control in the D-Bus install path when consuming unsigned metainfo before trusted metadata validation. A remote user can submit a crafted archive with a modified release version field to install a downgrade as a trusted update without a prompt.

Exploitation requires an active seat session with the unmodified auto-launched daemon, upstream polkit policy, and OnlyTrusted enabled.


2) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to mutate live device state and block a later legitimate update.

The vulnerability exists due to improper state management in the D-Bus install path when processing an unsigned archive before polkit authorization and trust validation. A remote user can submit a crafted archive to mutate live device state and block a later legitimate update.

Scope is limited to affected MD_SET_* device classes and unconditionally copied fields. The rejecting install attempt can occur without a polkit call.


3) Improper Authorization (CVE-ID: N/A)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to retarget a signed payload to a sibling device.

The vulnerability exists due to improper access control in the D-Bus install path when consuming unsigned routing metadata before trusted metadata validation. A remote user can submit a crafted archive with modified GUID or protocol fields to retarget a signed payload to a sibling device.

The demonstrated impact was limited to an emulator sibling module, and the advisory does not claim that every real hardware plugin accepts the payload.


Remediation

Install update from vendor's website.