CVE-2021-3802: Input Validation
A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.
Other sources
Several user-accessible mount helpers use insecure defaults which allow ext2/3/4 file systems to cause a denial of service (kernel panic) upon mounting a crafted image. This is especially relevant when mounts can be caused by unprivileged users or are configured to happen automatically and completely unauthorized.
External Reference:
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-045.txt
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3802?
CVE-2021-3802 is a vulnerability found in udisks2 that allows an attacker to input a specially crafted image file or USB leading to kernel panic.
What is the highest threat from CVE-2021-3802?
The highest threat from CVE-2021-3802 is to system availability.
Which software versions are affected by CVE-2021-3802?
Udisks version up to exclusive 2.9.4, Fedora version 34, and Redhat Enterprise Linux version 8.0 are affected by CVE-2021-3802.
How severe is CVE-2021-3802?
CVE-2021-3802 has a severity score of 4.2, indicating a medium severity level.
How can I fix CVE-2021-3802?
To fix CVE-2021-3802, update Udisks2 to version 2.9.5 or later, Fedora to the patched version, or Redhat Enterprise Linux to a fixed version.