UDisks
cpe:2.3:a:udisks_project:udisks:*:*:*:*:*:*:*
A vulnerability exists in the Udisks daemon that permits unprivileged users to create loop devices through the D-BUS system. This issue arises because the loop device handler, which processes D-BUS requests, fails to properly validate the lower bound of an index parameter, allowing negative values. Exploitation of this flaw can lead to a crash of the Udisks daemon or facilitate local privilege escalation by accessing files owned by privileged users.
Exploitation of this vulnerability can cause a segmentation fault, crashing the Udisks daemon. Additionally, it can be exploited for local privilege escalation, allowing access to files owned by privileged users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.