First published: Fri Jul 22 2016(Updated: )
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Linux | =15.10 | |
Ubuntu Linux | =16.04 | |
eCryptfs-utils | <=110 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8946 is considered a medium severity vulnerability due to its potential for unauthorized access to sensitive information.
To fix CVE-2015-8946, upgrade eCryptfs-utils to version 111 or newer or ensure proper configuration to prevent unencrypted swap activation.
CVE-2015-8946 affects Ubuntu 15.10 and Ubuntu 16.04 LTS with specific versions of eCryptfs-utils prior to 111.
CVE-2015-8946 is a local information disclosure vulnerability that allows unauthorized users to access sensitive data.
CVE-2015-8946 involves the ecryptfs-setup-swap utility within eCryptfs, which manages encrypted swap space.