CVE-2019-13178

EUVD-2019-4702
modules/luksbootkeyfile/main.py in Calamares versions 3.1 through 3.2.10 has a race condition between the time when the LUKS encryption keyfile is created and when secure permissions are set.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
calamarescalamares
3.1 ≤
𝑥
≤ 3.2.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
calamares
bookworm
3.2.61-1
fixed
bullseye
3.2.36-1
fixed
sid
3.3.9-1
fixed
trixie
3.3.9-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
calamares
bionic
needed
cosmic
ignored
disco
ignored
eoan
ignored
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
dne
References