CVE-2019-13178
Summary
| CVE | CVE-2019-13178 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-02 23:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | modules/luksbootkeyfile/main.py in Calamares versions 3.1 through 3.2.10 has a race condition between the time when the LUKS encryption keyfile is created and when secure permissions are set. |
Risk And Classification
Problem Types: CWE-362
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1726565 – (CVE-2019-13178) CVE-2019-13178 calamares: race condition in modules/luksbootkeyfile/main.py | MISC | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Bug #1835095 “Lubuntu initrd images leaking cryptographic secret...” : Bugs : calamares package : Ubuntu | MISC | bugs.launchpad.net | Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 29 Update: calamares-3.2.11-1.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 30 Update: calamares-3.2.11-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Calamares Initramfs Weakness – Calamares – The universal installer framework | CONFIRM | calamares.io | Third Party Advisory |
| [SECURITY] Fedora 29 Update: calamares-3.2.11-1.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Full disk encryption with LUKS (including /boot) · Pavel Kogan | MISC | www.pavelkogan.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2655-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Bug #1835096 “Unprivileged user can access LUKS keyfile” : Bugs : initramfs-tools package : Ubuntu | MISC | bugs.launchpad.net | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2654-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Unsafe generation of initramfs during FDE · Issue #1191 · calamares/calamares · GitHub | MISC | github.com | Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 30 Update: calamares-3.2.11-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [security-announce] openSUSE-SU-2019:2628-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Linux Mint encryption · Pavel Kogan | MISC | www.pavelkogan.com | Third Party Advisory |
| Race condition in changing permissions · Issue #1190 · calamares/calamares · GitHub | MISC | github.com | Issue Tracking, Third Party Advisory |
| Calamares 3.2.11 released - Calamares | CONFIRM | calamares.io | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.