Security Advisory

CVE-2024-38394

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-06-15 00:00:00
Last updated 2024-11-12 20:55:53
Assigner mitre
CVSS score 4.3
State PUBLISHED

Description

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."