Format string error in udisks - CVE-2018-17336
Published: January 30, 2024
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a format string error in udisks_log in udiskslogging.c. A local user can supply a specially crafted input that contains format string specifiers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label.
Affected software
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Fedora
IBM Security Guardium
udisks2 (Red Hat package)
udisks2
How to mitigate CVE-2018-17336
udisks2 - addressed in versions 2.7.6-2.fc27, 2.7.6-2.fc28, 2.8.1-1.fc29