Input validation error in luksmeta - CVE-2025-11568

 

Input validation error in luksmeta - CVE-2025-11568

Published: November 17, 2025


Vulnerability identifier: #VU118558
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11568
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to corrupt stored information.

The vulnerability exists due to insufficient input validation in the luksmeta utility when used with the LUKS1 disk encryption format. The utility fails to correctly validate the available space, causing the metadata to overwrite and corrupt the user's encrypted data.. A local user can write a large amount of metadata to an encrypted device and cause permanent loss of the stored information.


Affected software

luksmeta
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
openEuler
Fedora
libluksmeta
libluksmeta-devel
luksmeta
luksmeta (Red Hat package)
luksmeta-debuginfo
luksmeta-debugsource
luksmeta-devel
luksmeta-help

How to mitigate CVE-2025-11568

Install updates from vendor's website.

luksmeta - update to 10
libluksmeta - addressed in versions 9-4, 9-4.0.1
libluksmeta-devel - addressed in versions 9-4, 9-4.0.1
luksmeta - addressed in versions 9-4, 9-4.0.1
luksmeta (Red Hat package) - update to 9-4.el8_10.1
luksmeta - update to 9-7
luksmeta-debuginfo - update to 9-7
luksmeta-debugsource - update to 9-7
luksmeta-devel - update to 9-7
luksmeta-help - update to 9-7
luksmeta - addressed in versions 10-1.fc41, 10-1.fc42, 10-1.fc43

External References

Related Security Bulletins