CVE-2024-38394

EUVD-2024-37298
Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Debian logo
Debian Releases
Debian Product
Codename
gnome-settings-daemon
bookworm
unimportant
bullseye
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnome-settings-daemon
bionic
not-affected
focal
not-affected
jammy
not-affected
mantic
ignored
noble
not-affected
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gnome-settings-daemon
suse enterprise desktop 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise desktop 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise desktop 15 SP7
45.1-150700.7.3
fixed
suse enterprise sap 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise sap 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise sap 15 SP7
45.1-150700.7.3
fixed
suse enterprise server 15 SP4
41.0-150400.3.3.1
fixed
suse enterprise server 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise server 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise server 15 SP7
45.1-150700.7.3
fixed
gnome-settings-daemon-devel
suse enterprise desktop 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise desktop 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise desktop 15 SP7
45.1-150700.7.3
fixed
suse enterprise sap 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise sap 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise sap 15 SP7
45.1-150700.7.3
fixed
suse enterprise server 15 SP4
41.0-150400.3.3.1
fixed
suse enterprise server 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise server 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise server 15 SP7
45.1-150700.7.3
fixed
gnome-settings-daemon-lang
suse enterprise desktop 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise desktop 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise desktop 15 SP7
45.1-150700.7.3
fixed
suse enterprise sap 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise sap 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise sap 15 SP7
45.1-150700.7.3
fixed
suse enterprise server 15 SP4
41.0-150400.3.3.1
fixed
suse enterprise server 15 SP5
41.0-150500.4.3.1
fixed
suse enterprise server 15 SP6
45.1-150600.3.3.1
fixed
suse enterprise server 15 SP7
45.1-150700.7.3
fixed