CVE-2023-36476: `calamares-nixos-extensions` LUKS keyfile exposure
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions version 0.3.12 and prior who installed NixOS through the graphical calamares installer, with an unencrypted /boot, on either non-UEFI systems or with a LUKS partition different from / have their LUKS key file in /boot as a plaintext CPIO archive attached to their NixOS initrd. A patch is available and anticipated to be part of version 0.3.13 to backport to NixOS 22.11, 23.05, and unstable channels. Expert users who have a copy of their data may, as a workaround, re-encrypt the LUKS partition(s) themselves.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
calamares-nixos-extensionsto a version that resolves this vulnerability.Fixed in 0.3.13 - Operational
For expert users with a copy of their data, re-encrypt the LUKS partition(s) themselves as a workaround.
- Operational
If you are using calamares-nixos-extensions version 0.3.12 or prior and installed NixOS with the graphical calamares installer with an unencrypted /boot on either non-UEFI systems or with a LUKS partition different from /, locate the LUKS key file placed in /boot as a plaintext CPIO archive attached to your NixOS initrd and take remediation steps to address that plaintext exposure (for example, by re-encrypting the LUKS partition(s) as described above).
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36476?
CVE-2023-36476 is classified as a high severity vulnerability affecting the calamares-nixos-extensions package.
How do I fix CVE-2023-36476?
To fix CVE-2023-36476, users should update to calamares-nixos-extensions version 0.3.13 or later.
Who is affected by CVE-2023-36476?
Users of calamares-nixos-extensions version 0.3.12 and prior, who installed NixOS using the graphical calamares installer with an unencrypted /boot, are affected by CVE-2023-36476.
What does CVE-2023-36476 impact?
CVE-2023-36476 impacts the security configuration of NixOS installations utilizing the calamares installer.
Is an unencrypted /boot the only way to be affected by CVE-2023-36476?
Yes, having an unencrypted /boot during the installation through the graphical calamares installer is necessary to be affected by CVE-2023-36476.