Udisks Project maintains a narrowly scoped disk-management daemon for Linux systems that provides volume and device control through a system service, a role that gives its vulnerabilities direct bearing on system integrity despite the small product footprint. The durable signal centers on input-validation weaknesses and improper handling of file uploads in the core udisks product, reflecting the parsing and access-control demands of a privileged storage interface. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Udisks Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4661HIGH udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. | Nov 13, 2019 | 7.8 | 24 | NO | NO |
CVE-2021-3802MEDIUM A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to | Nov 29, 2021 | 4.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Udisks Project.
Media articles that mention a CVE ID that affects a product developed by Udisks Project — matched by CVE ID, not by vendor name.