#VU23408 Race condition in Calamares - CVE-2019-13178

 

#VU23408 Race condition in Calamares - CVE-2019-13178

Published: December 5, 2019


Vulnerability identifier: #VU23408
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-13178
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Calamares
Software vendor:
Calamares

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in modules/luksbootkeyfile/main.py when creating LUKS encryption keyfile. A local user can exploit the race and gain unauthorized access to sensitive information in the encryption file while the application sets permissions on the file.


Remediation

Install updates from vendor's website.

External links