CVE-2019-13178

modules/luksbootkeyfile/main.py in Calamares versions 3.1 through 3.2.10 has a race condition between the time when the LUKS encryption keyfile is created and when secure permissions are set.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
calamarescalamares
3.1 ≤
𝑥
≤ 3.2.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
calamares
bullseye
3.2.36-1
fixed
bookworm
3.2.61-1
fixed
sid
3.3.9-1
fixed
trixie
3.3.9-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
calamares
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
needed
impish
ignored
hirsute
ignored
groovy
ignored
focal
needed
eoan
ignored
disco
ignored
cosmic
ignored
bionic
needed
xenial
dne
trusty
dne
References