Incorrect authorization in USBGuard - CVE-2019-25058
Published: November 29, 2022
Vulnerability identifier: #VU69702
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-25058
CWE-ID: CWE-863
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to unspecified error within the usbguard-dbus daemon. A local user can allow all USB devices to be connected in the future.
Affected software
USBGuard
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
usbguard-devel
usbguard-tools
usbguard-dbus
usbguard
usbguard-debugsource
usbguard-debuginfo
usbguard-help
usbguard-applet-qt
usbguard (Red Hat package)
usbguard-notifier
usbguard-selinux
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
usbguard-devel
usbguard-tools
usbguard-dbus
usbguard
usbguard-debugsource
usbguard-debuginfo
usbguard-help
usbguard-applet-qt
usbguard (Red Hat package)
usbguard-notifier
usbguard-selinux
How to mitigate CVE-2019-25058
Install updates from vendor's website.
USBGuard - update to 1.1.0
usbguard-devel - update to 0.7.2-7
usbguard-tools - update to 0.7.2-7
usbguard-dbus - update to 0.7.2-7
usbguard - update to 0.7.2-7
usbguard-debugsource - update to 0.7.2-7
usbguard-debuginfo - update to 0.7.2-7
usbguard-help - update to 0.7.2-7
usbguard-applet-qt - update to 0.7.2-7
usbguard (Red Hat package) - addressed in versions 1.0.0-2.el8_4.1, 1.0.0-8.el8_6.1, 1.0.0-8.el8_7.2, 1.0.0-10.el9_0.1, 1.0.0-10.el9_1.2
usbguard - update to 1.0.0-8.0.1
usbguard-dbus - update to 1.0.0-8.0.1
usbguard-notifier - update to 1.0.0-8.0.1
usbguard-tools - update to 1.0.0-8.0.1
usbguard-selinux - update to 1.0.0-8.0.1
usbguard - addressed in versions 1.1.0-1.fc34, 1.1.0-1.fc35, 1.1.0-1.fc36, 1.1.0-1.fc37
usbguard-devel - update to 0.7.2-7
usbguard-tools - update to 0.7.2-7
usbguard-dbus - update to 0.7.2-7
usbguard - update to 0.7.2-7
usbguard-debugsource - update to 0.7.2-7
usbguard-debuginfo - update to 0.7.2-7
usbguard-help - update to 0.7.2-7
usbguard-applet-qt - update to 0.7.2-7
usbguard (Red Hat package) - addressed in versions 1.0.0-2.el8_4.1, 1.0.0-8.el8_6.1, 1.0.0-8.el8_7.2, 1.0.0-10.el9_0.1, 1.0.0-10.el9_1.2
usbguard - update to 1.0.0-8.0.1
usbguard-dbus - update to 1.0.0-8.0.1
usbguard-notifier - update to 1.0.0-8.0.1
usbguard-tools - update to 1.0.0-8.0.1
usbguard-selinux - update to 1.0.0-8.0.1
usbguard - addressed in versions 1.1.0-1.fc34, 1.1.0-1.fc35, 1.1.0-1.fc36, 1.1.0-1.fc37
External References
- https://github.com/USBGuard/usbguard/pull/531
- https://github.com/USBGuard/usbguard/issues/273
- https://github.com/USBGuard/usbguard/issues/403
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B3HQVTHHJFQLSWSXA7W3ZHRF72YMPI46/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B2ET6DU4IA64M6TMQ4X3SG2L6TRPLDN6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D4QO5J5YEWVX27QXYOGL3BDRV3KXNRQI/
- https://lists.debian.org/debian-lts-announce/2022/04/msg00010.html
Related Security Bulletins
- Security restrictions bypass in USBGuard
- Red Hat Enterprise Linux 8.4 Extended Update Support update for usbguard
- Red Hat Enterprise Linux 8.6 Extended Update Support update for usbguard
- Red Hat Enterprise Linux 9.0 Extended Update Support update for usbguard
- Red Hat Enterprise Linux 8 update for usbguard
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 9 update for usbguard
- openEuler 22.03 LTS update for usbguard
- Fedora 37 update for usbguard
- Fedora 35 update for usbguard
- Fedora 34 update for usbguard
- Fedora 36 update for usbguard
- Anolis OS update for usbguard