Fedora alert FEDORA-2025-4f28b95d7e (libblockdev)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 41 Update: libblockdev-3.2.2-1.fc41 | |
| Date: | Sat, 21 Jun 2025 02:13:23 +0000 | |
| Message-ID: | <20250621021323.BAC4F203A5A6@bastion01.iad2.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4f28b95d7e 2025-06-21 02:10:24.663271+00:00 -------------------------------------------------------------------------------- Name : libblockdev Product : Fedora 41 Version : 3.2.2 Release : 1.fc41 URL : https://github.com/storaged-project/libblockdev Summary : A library for low-level manipulation with block devices Description : The libblockdev is a C library with GObject introspection support that can be used for doing low-level operations with block devices like setting up LVM, BTRFS, LUKS or MD RAID. The library uses plugins (LVM, BTRFS,...) and serves as a thin wrapper around its plugins' functionality. All the plugins, however, can be used as standalone libraries. One of the core principles of libblockdev is that it is stateless from the storage configuration's perspective (e.g. it has no information about VGs when creating an LV). -------------------------------------------------------------------------------- Update Information: Don't allow suid and dev set on fs resize (Thomas.Blume) -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 18 2025 Vojtech Trefny <vtrefny@redhat.com> - 3.2.2-1 - Don't allow suid and dev set on fs resize (Thomas.Blume) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373307 - libblockdev allegedly exploitable via the udisks daemon included by default on most Linux distributions, and allows an “allow_active” user to gain full root privileges (CVE-2025-6019) https://bugzilla.redhat.com/show_bug.cgi?id=2373307 [ 2 ] Bug #2373715 - CVE-2025-6019 libblockdev: LPE from allow_active to root in libblockdev via udisks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2373715 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4f28b95d7e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
Attachment: None (type=text/plain)
-- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
