UBUNTU-CVE-2024-38394

Source
https://ubuntu.com/security/CVE-2024-38394
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-38394
Withdrawn
2025-06-23T15:58:30Z
Published
2024-06-16T00:15:00Z
Modified
2024-06-16T00:15:00Z
Summary
[none]
Details

** DISPUTED ** Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."

References

Affected packages

Ubuntu:20.04:LTS
gnome-settings-daemon

Package

Name
gnome-settings-daemon
Purl
pkg:deb/ubuntu/gnome-settings-daemon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.34.1-1ubuntu1
3.34.1-1ubuntu2
3.35.91-1ubuntu1
3.36.0-1ubuntu1
3.36.0-1ubuntu2
3.36.1-0ubuntu1
3.36.1-0ubuntu1.1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"
Ubuntu:22.04:LTS
gnome-settings-daemon

Package

Name
gnome-settings-daemon
Purl
pkg:deb/ubuntu/gnome-settings-daemon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

40.*
40.0.1-1ubuntu3
41.*
41.0-2ubuntu1
41.0-4ubuntu1
Other
42~alpha-1ubuntu1
42.*
42.1-1ubuntu1
42.1-1ubuntu2
42.1-1ubuntu2.1
42.1-1ubuntu2.2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"
Ubuntu:24.04:LTS
gnome-settings-daemon

Package

Name
gnome-settings-daemon
Purl
pkg:deb/ubuntu/gnome-settings-daemon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

45.*
45.0-1ubuntu1
45.1-1ubuntu1
Other
46~beta-1ubuntu1
46~beta-2ubuntu6
46~beta-2ubuntu7
46~beta-2ubuntu8
46.*
46.0-1ubuntu1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"
Ubuntu:Pro:16.04:LTS
gnome-settings-daemon

Package

Name
gnome-settings-daemon
Purl
pkg:deb/ubuntu/gnome-settings-daemon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.16.3-0ubuntu1
3.16.3-0ubuntu2
3.18.1-1ubuntu1
3.18.2-0ubuntu2
3.18.2-0ubuntu3
3.18.2-0ubuntu3.1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"
Ubuntu:Pro:18.04:LTS
gnome-settings-daemon

Package

Name
gnome-settings-daemon
Purl
pkg:deb/ubuntu/gnome-settings-daemon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.26.1-0ubuntu5
3.26.2-0ubuntu1
3.26.2-0ubuntu2
3.26.2-0ubuntu3
3.27.91-0ubuntu1
3.27.92-0ubuntu1
3.28.0-0ubuntu1
3.28.0-0ubuntu2
3.28.1-0ubuntu1
3.28.1-0ubuntu1.1
3.28.1-0ubuntu1.2
3.28.1-0ubuntu1.3

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"