udisks2-2.8.4-1.0.1.el7.AXS7
エラータID: AXSA:2025-11447:04
リリース日:
2025/12/04 Thursday - 16:39
題名:
udisks2-2.8.4-1.0.1.el7.AXS7
影響のあるチャネル:
Asianux Server 7 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- udisks2 には、メモリ領域の範囲外読み取りの問題があるため、
ローカルの攻撃者により、サービス拒否攻撃 (プロセスのクラッシュ)
や特権昇格を可能とする脆弱性が存在します。(CVE-2025-8067)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2025-8067
A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the file descriptor list and index specifying the file where the loop device should be backed. The function itself validates the index value to ensure it isn't bigger than the maximum value allowed. However, it fails to validate the lower bound, allowing the index parameter to be a negative value. Under these circumstances, an attacker can cause the UDisks daemon to crash or perform a local privilege escalation by gaining access to files owned by privileged users.
A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the file descriptor list and index specifying the file where the loop device should be backed. The function itself validates the index value to ensure it isn't bigger than the maximum value allowed. However, it fails to validate the lower bound, allowing the index parameter to be a negative value. Under these circumstances, an attacker can cause the UDisks daemon to crash or perform a local privilege escalation by gaining access to files owned by privileged users.
追加情報:
N/A
ダウンロード:
Asianux Server 7 for x86_64
- libudisks2-2.8.4-1.0.1.el7.AXS7.i686.rpm
MD5: 9ff6b48b1f5b9c03ad39e09025ffe50e
SHA-256: 7b92a2ced391f71f7fe34ae3caa3ffb906465658d69c090ed4939ffbb8a4262c
Size: 125.53 kB - libudisks2-2.8.4-1.0.1.el7.AXS7.x86_64.rpm
MD5: c44b19e232f4e5081285261e0a486913
SHA-256: ea3ccc55f166ae961c74dd678322e008e571da64a0b1d7376081fd9c10407a6f
Size: 128.84 kB - libudisks2-devel-2.8.4-1.0.1.el7.AXS7.i686.rpm
MD5: e21150bbb54f66276887d5a307976e55
SHA-256: 9855c246c9fc236fca2e9a7e9369b0ceb5be41bc39dd56c46fd0e4872f34c6b8
Size: 352.24 kB - libudisks2-devel-2.8.4-1.0.1.el7.AXS7.x86_64.rpm
MD5: 7cacfd8ba32de65c61bfd6e23170405f
SHA-256: 5b63e934b49326f82e26be476d00ad1b7aaff4c3d63f549783b0fed069098858
Size: 352.22 kB - udisks2-2.8.4-1.0.1.el7.AXS7.x86_64.rpm
MD5: 19adcac8f2cc9a1fca83ecc61dfcd176
SHA-256: 2df49a778d2ccf91a5f7c52439755bdfdf79b58eda5201f567f19209de53e3d8
Size: 440.79 kB - udisks2-iscsi-2.8.4-1.0.1.el7.AXS7.x86_64.rpm
MD5: 82e658764ef438f9c3049edabe598160
SHA-256: 03dfee379558e0dba9fcb1b8362d71956a5117ad564f95992864318f209e2590
Size: 36.50 kB - udisks2-lsm-2.8.4-1.0.1.el7.AXS7.x86_64.rpm
MD5: 6f7851d727152753baf030ff519b4c6b
SHA-256: 7e5ecfafc255687d02b3c70405de7cbc48188a38efe9623eff1fc00a1f5c361a
Size: 37.58 kB - udisks2-lvm2-2.8.4-1.0.1.el7.AXS7.x86_64.rpm
MD5: 5db164da00723f74065a7fa48c9c6a0e
SHA-256: af80a38e5499973141c63594709ac3eefcddf6c682c07fed7676b58a11355115
Size: 61.24 kB