CVE-2015-8946: Input Validation
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8946?
CVE-2015-8946 is considered a medium severity vulnerability due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2015-8946?
To fix CVE-2015-8946, upgrade eCryptfs-utils to version 111 or newer or ensure proper configuration to prevent unencrypted swap activation.
Which versions of Ubuntu are affected by CVE-2015-8946?
CVE-2015-8946 affects Ubuntu 15.10 and Ubuntu 16.04 LTS with specific versions of eCryptfs-utils prior to 111.
What type of vulnerability is CVE-2015-8946?
CVE-2015-8946 is a local information disclosure vulnerability that allows unauthorized users to access sensitive data.
What software component is involved in CVE-2015-8946?
CVE-2015-8946 involves the ecryptfs-setup-swap utility within eCryptfs, which manages encrypted swap space.