{"api_version":"1","generated_at":"2026-07-23T11:55:42+00:00","cve":"CVE-2019-13179","urls":{"html":"https://cve.report/CVE-2019-13179","api":"https://cve.report/api/cve/CVE-2019-13179.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-13179","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-13179"},"summary":{"title":"CVE-2019-13179","description":"Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-07-02 23:15:00","updated_at":"2023-11-07 03:03:00"},"problem_types":["CWE-522"],"metrics":[],"references":[{"url":"https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835095","name":"https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835095","refsource":"MISC","tags":["Exploit","Issue Tracking","Third Party Advisory"],"title":"Bug #1835095 “Lubuntu initrd images leaking cryptographic secret...” : Bugs : calamares package : Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R2ZDQRGBGRVRW5LPJWKUNS3M66LZ3KYC/","name":"FEDORA-2019-e61a85c2bb","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 29 Update: calamares-3.2.11-1.fc29 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q57BOTBA2J5U4GVKUP7N2PD5H7B3BVUU/","name":"FEDORA-2019-50ee491d76","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 30 Update: calamares-3.2.11-1.fc30 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://calamares.io/calamares-cve-2019/","name":"https://calamares.io/calamares-cve-2019/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Calamares Initramfs Weakness – Calamares – The universal installer framework","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1726542","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1726542","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"1726542 – (CVE-2019-13179) CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R2ZDQRGBGRVRW5LPJWKUNS3M66LZ3KYC/","name":"FEDORA-2019-e61a85c2bb","refsource":"","tags":[],"title":"[SECURITY] Fedora 29 Update: calamares-3.2.11-1.fc29 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835096","name":"https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835096","refsource":"MISC","tags":["Third Party Advisory"],"title":"Bug #1835096 “Unprivileged user can access LUKS keyfile” : Bugs : initramfs-tools package : Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/calamares/calamares/issues/1191","name":"https://github.com/calamares/calamares/issues/1191","refsource":"MISC","tags":["Exploit","Issue Tracking","Third Party Advisory"],"title":"Unsafe generation of initramfs during FDE · Issue #1191 · calamares/calamares · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q57BOTBA2J5U4GVKUP7N2PD5H7B3BVUU/","name":"FEDORA-2019-50ee491d76","refsource":"","tags":[],"title":"[SECURITY] Fedora 30 Update: calamares-3.2.11-1.fc30 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://calamares.io/calamares-3.2.11-is-out/","name":"https://calamares.io/calamares-3.2.11-is-out/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Calamares 3.2.11 released - Calamares","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-13179","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13179","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"13179","vulnerable":"1","versionEndIncluding":"3.2.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"calamares","cpe5":"calamares","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-13179","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835096","refsource":"MISC","name":"https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835096"},{"url":"https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835095","refsource":"MISC","name":"https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835095"},{"url":"https://github.com/calamares/calamares/issues/1191","refsource":"MISC","name":"https://github.com/calamares/calamares/issues/1191"},{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1726542","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1726542"},{"refsource":"CONFIRM","name":"https://calamares.io/calamares-3.2.11-is-out/","url":"https://calamares.io/calamares-3.2.11-is-out/"},{"refsource":"CONFIRM","name":"https://calamares.io/calamares-cve-2019/","url":"https://calamares.io/calamares-cve-2019/"},{"refsource":"FEDORA","name":"FEDORA-2019-50ee491d76","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q57BOTBA2J5U4GVKUP7N2PD5H7B3BVUU/"},{"refsource":"FEDORA","name":"FEDORA-2019-e61a85c2bb","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R2ZDQRGBGRVRW5LPJWKUNS3M66LZ3KYC/"}]}},"nvd":{"publishedDate":"2019-07-02 23:15:00","lastModifiedDate":"2023-11-07 03:03:00","problem_types":["CWE-522"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:calamares:calamares:*:*:*:*:*:*:*:*","versionEndIncluding":"3.2.10","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"13179","Ordinal":"151537","Title":"CVE-2019-13179","CVE":"CVE-2019-13179","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"13179","Ordinal":"1","NoteData":"Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"13179","Ordinal":"2","NoteData":"2019-07-02","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"13179","Ordinal":"3","NoteData":"2019-08-12","Type":"Other","Title":"Modified"}]}}}