{
  "version": "1",
  "package": [
    {
      "name": "udisks2",
      "layer": "meta-oe",
      "version": "2.10.1",
      "products": [
        {
          "product": "udisks",
          "cvesInRecord": "Yes"
        }
      ],
      "issue": [
        {
          "id": "CVE-2010-1149",
          "summary": "probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.",
          "scorev2": "2.1",
          "scorev3": "0.0",
          "vector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "status": "Patched",
          "link": "https://nvd.nist.gov/vuln/detail/CVE-2010-1149"
        },
        {
          "id": "CVE-2010-4661",
          "summary": "udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.",
          "scorev2": "4.6",
          "scorev3": "7.8",
          "vector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "status": "Patched",
          "link": "https://nvd.nist.gov/vuln/detail/CVE-2010-4661"
        },
        {
          "id": "CVE-2014-0004",
          "summary": "Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.",
          "scorev2": "6.9",
          "scorev3": "0.0",
          "vector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "status": "Patched",
          "link": "https://nvd.nist.gov/vuln/detail/CVE-2014-0004"
        },
        {
          "id": "CVE-2018-17336",
          "summary": "UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.",
          "scorev2": "4.6",
          "scorev3": "7.8",
          "vector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "status": "Patched",
          "link": "https://nvd.nist.gov/vuln/detail/CVE-2018-17336"
        },
        {
          "id": "CVE-2021-3802",
          "summary": "A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.",
          "scorev2": "6.3",
          "scorev3": "4.2",
          "vector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:N/A:C",
          "status": "Patched",
          "link": "https://nvd.nist.gov/vuln/detail/CVE-2021-3802"
        }
      ]
    }
  ]
}