Candidate: CVE-2021-3802 PublicDate: 2021-11-29 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3802 https://access.redhat.com/security/cve/CVE-2021-3802 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-045.txt https://github.com/storaged-project/udisks/releases/tag/udisks-2.9.4 Description: A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. Ubuntu-Description: Notes: Mitigation: Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=2003649 Priority: low Discovered-by: Stefan Walter Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H [4.2 MEDIUM] Patches_udisks2: upstream: https://github.com/storaged-project/udisks/commit/38d90a433bda0fc0f2a409f6baa12c3958893571 upstream_udisks2: released (2.9.4) trusty_udisks2: ignored (out of standard support) trusty/esm_udisks2: needs-triage xenial_udisks2: ignored (out of standard support) esm-infra/xenial_udisks2: needs-triage bionic_udisks2: needed focal_udisks2: needed hirsute_udisks2: ignored (reached end-of-life) impish_udisks2: not-affected (2.9.4-1) jammy_udisks2: not-affected (2.9.4-1) devel_udisks2: not-affected (2.9.4-1)