CVE-2024-38394: Medium severity gnome settings daemon vulnerability
Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38394?
CVE-2024-38394 has a high severity level due to the potential for unauthorized access to USB functionality.
How do I fix CVE-2024-38394?
To fix CVE-2024-38394, update the GNOME Settings Daemon to a version later than 46.0.
What are the potential impacts of CVE-2024-38394?
The potential impacts of CVE-2024-38394 include unauthorized access to certain Linux kernel USB functionalities, which may expose sensitive data.
Who is affected by CVE-2024-38394?
CVE-2024-38394 affects users of the GNOME Settings Daemon version 46.0 or earlier.
Can a remote attacker exploit CVE-2024-38394?
No, CVE-2024-38394 can only be exploited by a physically proximate attacker.