Race condition in Calamares - CVE-2019-13178

 

Race condition in Calamares - CVE-2019-13178

Published: December 5, 2019


Vulnerability identifier: #VU23408
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13178
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in modules/luksbootkeyfile/main.py when creating LUKS encryption keyfile. A local user can exploit the race and gain unauthorized access to sensitive information in the encryption file while the application sets permissions on the file.


Affected software

Calamares
Opensuse
SUSE Linux
Fedora
calamares

How to mitigate CVE-2019-13178

Install updates from vendor's website.

Calamares - update to 3.2.11
calamares - addressed in versions 3.2.11-1.fc29, 3.2.11-1.fc30

External References

Related Security Bulletins