CVE-2018-17336

UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
freedesktopudisks
2.8.0
canonicalubuntu_linux
18.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
udisks2
bookworm
2.9.4-4
fixed
bullseye
2.9.2-2+deb11u1
fixed
jessie
not-affected
sid
2.10.1-11
fixed
stretch
not-affected
trixie
2.10.1-11
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
udisks2
bionic
Fixed 2.7.6-3ubuntu0.2
released
trusty
not-affected
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libudisks2-0
suse enterprise desktop 15
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP1
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP2
2.8.1-1.39
fixed
suse enterprise desktop 15 SP3
2.8.1-1.39
fixed
suse enterprise desktop 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise desktop 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise sap 15
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP1
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP2
2.8.1-1.39
fixed
suse enterprise sap 15 SP3
2.8.1-1.39
fixed
suse enterprise sap 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise sap 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise server 15
2.6.5-3.7.2
fixed
suse enterprise server 15 SP1
2.6.5-3.7.2
fixed
suse enterprise server 15 SP2
2.8.1-1.39
fixed
suse enterprise server 15 SP3
2.8.1-1.39
fixed
suse enterprise server 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise server 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP7
2.9.2-150400.3.8.1
fixed
libudisks2-0-devel
suse enterprise desktop 15 SP2
2.8.1-1.39
fixed
suse enterprise desktop 15 SP3
2.8.1-1.39
fixed
suse enterprise desktop 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise desktop 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise sap 15 SP2
2.8.1-1.39
fixed
suse enterprise sap 15 SP3
2.8.1-1.39
fixed
suse enterprise sap 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise sap 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise server 15 SP2
2.8.1-1.39
fixed
suse enterprise server 15 SP3
2.8.1-1.39
fixed
suse enterprise server 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise server 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP7
2.9.2-150400.3.8.1
fixed
typelib-1_0-UDisks-2_0
suse enterprise desktop 15
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP1
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP2
2.8.1-1.39
fixed
suse enterprise desktop 15 SP3
2.8.1-1.39
fixed
suse enterprise desktop 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise desktop 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise sap 15
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP1
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP2
2.8.1-1.39
fixed
suse enterprise sap 15 SP3
2.8.1-1.39
fixed
suse enterprise sap 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise sap 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise server 15
2.6.5-3.7.2
fixed
suse enterprise server 15 SP1
2.6.5-3.7.2
fixed
suse enterprise server 15 SP2
2.8.1-1.39
fixed
suse enterprise server 15 SP3
2.8.1-1.39
fixed
suse enterprise server 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise server 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP7
2.9.2-150400.3.8.1
fixed
udisks2
suse enterprise desktop 15
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP1
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP2
2.8.1-1.39
fixed
suse enterprise desktop 15 SP3
2.8.1-1.39
fixed
suse enterprise desktop 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise desktop 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise sap 15
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP1
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP2
2.8.1-1.39
fixed
suse enterprise sap 15 SP3
2.8.1-1.39
fixed
suse enterprise sap 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise sap 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise server 15
2.6.5-3.7.2
fixed
suse enterprise server 15 SP1
2.6.5-3.7.2
fixed
suse enterprise server 15 SP2
2.8.1-1.39
fixed
suse enterprise server 15 SP3
2.8.1-1.39
fixed
suse enterprise server 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise server 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP7
2.9.2-150400.3.8.1
fixed
udisks2-devel
suse enterprise desktop 15
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP1
2.6.5-3.7.2
fixed
suse enterprise sap 15
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP1
2.6.5-3.7.2
fixed
suse enterprise server 15
2.6.5-3.7.2
fixed
suse enterprise server 15 SP1
2.6.5-3.7.2
fixed
udisks2-lang
suse enterprise desktop 15
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP1
2.6.5-3.7.2
fixed
suse enterprise desktop 15 SP2
2.8.1-1.39
fixed
suse enterprise desktop 15 SP3
2.8.1-1.39
fixed
suse enterprise desktop 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise desktop 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise sap 15
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP1
2.6.5-3.7.2
fixed
suse enterprise sap 15 SP2
2.8.1-1.39
fixed
suse enterprise sap 15 SP3
2.8.1-1.39
fixed
suse enterprise sap 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise sap 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise sap 15 SP7
2.9.2-150400.3.8.1
fixed
suse enterprise server 15
2.6.5-3.7.2
fixed
suse enterprise server 15 SP1
2.6.5-3.7.2
fixed
suse enterprise server 15 SP2
2.8.1-1.39
fixed
suse enterprise server 15 SP3
2.8.1-1.39
fixed
suse enterprise server 15 SP4
2.9.2-150400.1.15
fixed
suse enterprise server 15 SP5
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP6
2.9.2-150400.3.3.1
fixed
suse enterprise server 15 SP7
2.9.2-150400.3.8.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libudisks2
RHEL 7
0:2.7.3-9.el7
fixed
libudisks2-devel
RHEL 7
0:2.7.3-9.el7
fixed
udisks2
RHEL 7
0:2.7.3-9.el7
fixed
udisks2-iscsi
RHEL 7
0:2.7.3-9.el7
fixed
udisks2-lsm
RHEL 7
0:2.7.3-9.el7
fixed
udisks2-lvm2
RHEL 7
0:2.7.3-9.el7
fixed