DEBIAN-CVE-2024-38394

Source
https://security-tracker.debian.org/tracker/CVE-2024-38394
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-38394.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-38394
Upstream
Published
2024-06-16T00:15:49Z
Modified
2026-09-15T09:03:07Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

References

Affected packages

Debian:12 / gnome-settings-daemon

Package

Name
gnome-settings-daemon
Purl
pkg:deb/debian/gnome-settings-daemon?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

43.*
43.0-4
Other
44~beta-1
44~rc-1
45~beta-1
45~rc-1
46~beta-1
46~beta-2
47~beta-1
47~rc-1
48~beta-1
48~rc-1
51~beta-1
51~beta-2
51~rc-1
44.*
44.0-1
44.1-1
44.1-2
45.*
45.0-1
45.0-2
45.1-1
46.*
46.0-1
46.0-2
46.0-3
46.0-4
46.0-5
47.*
47.1-1
47.1-2
47.2-1
48.*
48.0-1
48.1-1
48.1-2
49.*
49.0-1
49.1-1
49.1-2
49.1-3
49.1-4
49.1-5
50.*
50.0-1
50.0-2
50.1-1
51.*
51.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-38394.json"

Debian:13 / gnome-settings-daemon

Package

Name
gnome-settings-daemon
Purl
pkg:deb/debian/gnome-settings-daemon?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

48.*
48.1-1
48.1-2
49.*
49.0-1
49.1-1
49.1-2
49.1-3
49.1-4
49.1-5
50.*
50.0-1
50.0-2
50.1-1
Other
51~beta-1
51~beta-2
51~rc-1
51.*
51.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-38394.json"

Debian:14 / gnome-settings-daemon

Package

Name
gnome-settings-daemon
Purl
pkg:deb/debian/gnome-settings-daemon?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

48.*
48.1-1
48.1-2
49.*
49.0-1
49.1-1
49.1-2
49.1-3
49.1-4
49.1-5
50.*
50.0-1
50.0-2
50.1-1
Other
51~beta-1
51~beta-2
51~rc-1
51.*
51.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-38394.json"