Files
buildroot/package/udisks/udisks.mk
Raphaël Mélotte via buildroot a6c86f8511 package: udisks: add patches for CVE-2026-7867
This fixes the following vulnerability:
- CVE-2026-7867:
    A flaw was found in udisks2. A local attacker with an active console
    session can exploit insufficient authorization checking on the 'as-
    user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus
    method. This allows the attacker to spoof the 'as-user' parameter,
    mounting filesystems on behalf of arbitrary users, including
    privileged accounts. This can lead to local privilege escalation
    through mount point injection and manipulation of the mount namespace
    visible to privileged users.
    https://www.cve.org/CVERecord?id=CVE-2026-7867

Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>7
(alternative to commit 93049b2559)
[Titouan:
    - Add upstream, SoB, CVE tags in patches
    - Add UDISKS_IGNORE_CVES entry
    - Add CVE description in the commit message
]
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-28 15:57:20 +02:00

56 lines
1.4 KiB
Makefile

################################################################################
#
# udisks
#
################################################################################
UDISKS_VERSION = 2.10.2
UDISKS_SOURCE = udisks-$(UDISKS_VERSION).tar.bz2
UDISKS_SITE = https://github.com/storaged-project/udisks/releases/download/udisks-$(UDISKS_VERSION)
UDISKS_LICENSE = GPL-2.0+
UDISKS_LICENSE_FILES = COPYING
UDISKS_CPE_ID_VENDOR = freedesktop
UDISKS_INSTALL_STAGING = YES
UDISKS_DEPENDENCIES = \
host-pkgconf \
dbus \
dbus-glib \
libatasmart \
libblockdev \
libgudev \
parted \
polkit \
sg3_utils \
udev \
util-linux
UDISKS_CONF_OPTS = \
--disable-acl \
--disable-bcache \
--disable-btrfs \
--disable-introspection \
--disable-iscsi \
--disable-lsm \
--disable-lvm2 \
--disable-lvmcache \
--disable-man \
--disable-rpath \
--disable-vdo \
--disable-zram
# 0001-udiskslinuxfilesystem-Separate-real-caller-identity-.patch
# 0002-udiskslinuxfilesystem-Rework-fstab-mount-authorizati.patch
# 0003-udiskslinuxfilesystem-Log-real-caller-uid-for-as-use.patch
# 0004-udisksdaemonutil-Pass-as-user-target-to-polkit-detai.patch
# 0005-tests-Add-security-tests-for-as-user-mount-authoriza.patch
UDISKS_IGNORE_CVES += CVE-2026-7867
ifeq ($(BR2_PACKAGE_UDISKS_FHS_MEDIA),y)
UDISKS_CONF_OPTS += --enable-fhs-media
else
UDISKS_CONF_OPTS += --disable-fhs-media
endif
$(eval $(autotools-package))