A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.
Last updated 25 August 2025
Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.
Bastian Blank reported: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687
an information leak in the way udisks's disks and storage device management daemon passed sensitive device mapper table information to userspace processes via the udev interface. Local attacker could use this flaw to conduct subsequent unauthorized operations on storage device(s), which should be otherwise protected by encryption / luks passphrase knowledge.
Upstream bug report: [2] https://bugs.freedesktop.org/showbug.cgi?id=27494
Upstream patch: [3] http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4
References: [4] https://bugzilla.novell.com/showbug.cgi?id=594261
CVE Request: [5] http://www.openwall.com/lists/oss-security/2010/04/06/5