Skip to content

udev: local root execution via malicious hardware devices and unsanitized kernel output

Moderate
bluca published GHSA-vpfq-8p5f-jcqx Mar 23, 2026

Package

udev (linux)

Affected versions

< 260

Patched versions

260 259.5 258.7 257.13

Description

Impact

udev's scsi_id and v4l_id helper binaries, which parse input from the kernel, are vulnerable to malicious devices being plugged in, with intentionally crafted properties exposed to the respective kernel drivers, that send them down to userspace without sanitization.

For v4l_id, the ID_V4L_PRODUCT property is derived from the USB descriptor, and a custom device can set it to foo\nREMOVE_CMD=/path/to/exe to have udev run the selected executable as root.

For scsi_id, the ID_SCSI_SERIAL property is derived from the hardware's SCSI serial, which can be crafted to contain \n SYSTEMD_WANTS=foobar.service so that it can be used to activate a unit of the attacker's choice, including debug-shell.service which spawns a root console.

Patches

v260 16325b3 54f880b
v259.5 3513862 4425d85
v258.7 c20d21e 75c585b
v257.13 03bb697 5887e72

Workarounds

Disable the v4l and iscsi drivers in the kernel

References

Originally reported on yeswehack.com as YWH-PGM9780-98 and YWH-PGM9780-99

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Physical
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE ID

No known CVE

Weaknesses

No CWEs

Credits