Where
-Infinity
0

Vendor Risk Score

See how luksmeta compares to other vendors in security performance

View Risk Score →
Severity
5.1
AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L

A flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata to a Linux Unified Key Setup (LUKS) device. Due to incorrect boundary calculations and flawed overlap detection, new metadata entries can be written beyond available free space or over existing records. This issue can corrupt stored encrypted payload data or existing metadata, potentially rendering the affected data inaccessible.

1 / 2
Source: MITRE
First published (updated )
Severity
4

A flaw was found in luksmeta. The gap allocator used by luksmetasave() to find free space in a LUKS1 header does not correctly bound where a new metadata entry may be written. When metadata slot 0 already holds an entry, findgap() computes its upper write limit using slot 0's own byte offset instead of the true end of the free-space gap, allowing luksmetasave() to write a new entry past the end of the gap into the start of the encrypted payload area and corrupt stored data. Separately, the overlap() placement check only detects a new entry that covers the start or end of an existing entry, and misses a new entry that falls entirely within an existing entry longer than two pages (8192 bytes); this allows a new entry to overwrite part of an existing one, corrupting it so that it can no longer be loaded. Both conditions require an attacker who already has root-level write access to a LUKS1-formatted device; LUKS2 is not affected. Exploitation does not grant additional privileges or disclose data; the impact is limited to data corruption.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203