See how luksmeta compares to other vendors in security performance
A flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata to a Linux Unified Key Setup (LUKS) device. Due to incorrect boundary calculations and flawed overlap detection, new metadata entries can be written beyond available free space or over existing records. This issue can corrupt stored encrypted payload data or existing metadata, potentially rendering the affected data inaccessible.
A flaw was found in luksmeta. The gap allocator used by luksmetasave() to find free space in a LUKS1 header does not correctly bound where a new metadata entry may be written. When metadata slot 0 already holds an entry, findgap() computes its upper write limit using slot 0's own byte offset instead of the true end of the free-space gap, allowing luksmetasave() to write a new entry past the end of the gap into the start of the encrypted payload area and corrupt stored data. Separately, the overlap() placement check only detects a new entry that covers the start or end of an existing entry, and misses a new entry that falls entirely within an existing entry longer than two pages (8192 bytes); this allows a new entry to overwrite part of an existing one, corrupting it so that it can no longer be loaded. Both conditions require an attacker who already has root-level write access to a LUKS1-formatted device; LUKS2 is not affected. Exploitation does not grant additional privileges or disclose data; the impact is limited to data corruption.