{"id":"UBUNTU-CVE-2024-38394","details":"** DISPUTED ** Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of \"a new feature, not a CVE.\"","modified":"2024-06-16T00:15:00Z","published":"2024-06-16T00:15:00Z","withdrawn":"2025-06-23T15:58:30Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-38394"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-38394"},{"type":"REPORT","url":"https://pulsesecurity.co.nz/advisories/usbguard-bypass"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/gnome-settings-daemon/-/issues/780#note_2047914"}],"affected":[{"package":{"name":"gnome-settings-daemon","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/gnome-settings-daemon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.16.3-0ubuntu1","3.16.3-0ubuntu2","3.18.1-1ubuntu1","3.18.2-0ubuntu2","3.18.2-0ubuntu3","3.18.2-0ubuntu3.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"}},{"package":{"name":"gnome-settings-daemon","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/gnome-settings-daemon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.26.1-0ubuntu5","3.26.2-0ubuntu1","3.26.2-0ubuntu2","3.26.2-0ubuntu3","3.27.91-0ubuntu1","3.27.92-0ubuntu1","3.28.0-0ubuntu1","3.28.0-0ubuntu2","3.28.1-0ubuntu1","3.28.1-0ubuntu1.1","3.28.1-0ubuntu1.2","3.28.1-0ubuntu1.3"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"}},{"package":{"name":"gnome-settings-daemon","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gnome-settings-daemon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.34.1-1ubuntu1","3.34.1-1ubuntu2","3.35.91-1ubuntu1","3.36.0-1ubuntu1","3.36.0-1ubuntu2","3.36.1-0ubuntu1","3.36.1-0ubuntu1.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"}},{"package":{"name":"gnome-settings-daemon","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gnome-settings-daemon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["40.0.1-1ubuntu3","41.0-2ubuntu1","41.0-4ubuntu1","42~alpha-1ubuntu1","42.1-1ubuntu1","42.1-1ubuntu2","42.1-1ubuntu2.1","42.1-1ubuntu2.2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"}},{"package":{"name":"gnome-settings-daemon","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gnome-settings-daemon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["45.0-1ubuntu1","45.1-1ubuntu1","46~beta-1ubuntu1","46~beta-2ubuntu6","46~beta-2ubuntu7","46~beta-2ubuntu8","46.0-1ubuntu1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-38394.json"}}],"schema_version":"1.7.3"}