CVE-2023-36476: `calamares-nixos-extensions` LUKS keyfile exposure

Published Jun 29, 2023
·
Updated

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions version 0.3.12 and prior who installed NixOS through the graphical calamares installer, with an unencrypted /boot, on either non-UEFI systems or with a LUKS partition different from / have their LUKS key file in /boot as a plaintext CPIO archive attached to their NixOS initrd. A patch is available and anticipated to be part of version 0.3.13 to backport to NixOS 22.11, 23.05, and unstable channels. Expert users who have a copy of their data may, as a workaround, re-encrypt the LUKS partition(s) themselves.

Affected Software

1 affected component
NixOS calamares-nixos-extensions<0.3.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade calamares-nixos-extensions to a version that resolves this vulnerability.

    Fixed in 0.3.13
  2. Operational

    For expert users with a copy of their data, re-encrypt the LUKS partition(s) themselves as a workaround.

  3. Operational

    If you are using calamares-nixos-extensions version 0.3.12 or prior and installed NixOS with the graphical calamares installer with an unencrypted /boot on either non-UEFI systems or with a LUKS partition different from /, locate the LUKS key file placed in /boot as a plaintext CPIO archive attached to your NixOS initrd and take remediation steps to address that plaintext exposure (for example, by re-encrypting the LUKS partition(s) as described above).

Event History

Jun 29, 2023
CVE Published
via MITRE·12:18 AM
Data Sourced
via MITRE·12:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-36476?

CVE-2023-36476 is classified as a high severity vulnerability affecting the calamares-nixos-extensions package.

2

How do I fix CVE-2023-36476?

To fix CVE-2023-36476, users should update to calamares-nixos-extensions version 0.3.13 or later.

3

Who is affected by CVE-2023-36476?

Users of calamares-nixos-extensions version 0.3.12 and prior, who installed NixOS using the graphical calamares installer with an unencrypted /boot, are affected by CVE-2023-36476.

4

What does CVE-2023-36476 impact?

CVE-2023-36476 impacts the security configuration of NixOS installations utilizing the calamares installer.

5

Is an unencrypted /boot the only way to be affected by CVE-2023-36476?

Yes, having an unencrypted /boot during the installation through the graphical calamares installer is necessary to be affected by CVE-2023-36476.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203