CVE-2023-0751: GELI silently omits the keyfile if read from stdin
Published Feb 8, 2023
·Updated
When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key file allowing trivial recovery of the master key.
Affected Software
18 affected components
FreeBSD FreeBSD=12.3
FreeBSD FreeBSD=12.3-p1
FreeBSD FreeBSD=12.3-p2
FreeBSD FreeBSD=12.3-p3
FreeBSD FreeBSD=12.3-p4
FreeBSD FreeBSD=12.3-p5
FreeBSD FreeBSD=12.4
FreeBSD FreeBSD=12.4-rc2-p1
FreeBSD FreeBSD=12.4-rc2-p2
FreeBSD FreeBSD=13.1
FreeBSD FreeBSD=13.1-b1-p1
FreeBSD FreeBSD=13.1-b2-p2
FreeBSD FreeBSD=13.1-p1
FreeBSD FreeBSD=13.1-p2
FreeBSD FreeBSD=13.1-p3
FreeBSD FreeBSD=13.1-p4
FreeBSD FreeBSD=13.1-p5
FreeBSD FreeBSD=13.1-rc1-p1
Remediation
Event History
Feb 8, 2023
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-0751?
The severity of CVE-2023-0751 is medium with a severity value of 6.5.
2
How does CVE-2023-0751 affect Freebsd Freebsd 12.3?
CVE-2023-0751 affects Freebsd Freebsd 12.3.
3
How can I fix CVE-2023-0751?
To fix CVE-2023-0751, update to the latest version of Freebsd Freebsd or apply the necessary patches.
4
Where can I find more information about CVE-2023-0751?
You can find more information about CVE-2023-0751 on the FreeBSD Security Advisories website.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-0751?
The Common Weakness Enumeration (CWE) ID for CVE-2023-0751 is 20.