Michael Imfeld discovered an out-of-bounds read vulnerability in udisks2, a D-Bus service to access and manipulate storage devices, which may result in denial of service (daemon process crash), or in mapping an internal file descriptor from the daemon process onto a loop device, resulting in local privilege escalation.
https://security-tracker.debian.org/tracker/DSA-5989-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-5989-1
Continue reading...

