CVE-2015-8946
published 2016-07-22CVE-2015-8946: ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain…
PriorityP48low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.35%
27.5th percentile
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ecryptfs-utils | < ecryptfs-utils 111-1 (bookworm) | ecryptfs-utils 111-1 (bookworm) |
| debian | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | <= 110 | — |
| ecryptfs | ecryptfs-utils | >= 0 < 111-1 | 111-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 111-1 | 111-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 111-1 | 111-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 111-1 | 111-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 111-0ubuntu1.1 | 111-0ubuntu1.1 |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
vendor_redhat·2016-07-06·CVSS 3.3
CVE-2016-6224 [LOW] CWE-200 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
Package: ecryptfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: ecryptfs-utils (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-6224: ecryptfs-utils - ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition ...
vendor_debian·2016·CVSS 3.3
CVE-2016-6224 [LOW] CVE-2016-6224: ecryptfs-utils - ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition ...
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
vendor_redhat·2015-08-04·CVSS 3.3
CVE-2015-8946 [LOW] CWE-200 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
Package: ecryptfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: ecryptfs-utils (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2015-8946: ecryptfs-utils - ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap...
vendor_debian·2015·CVSS 3.3
CVE-2015-8946 [LOW] CVE-2015-8946: ecryptfs-utils - ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap...
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 111-1)
bullseye: resolved (fixed in 111-1)
forky: resolved (fixed in 111-1)
sid: resolved (fixed in 111-1)
trixie: resolved (fixed in 111-1)
GHSA
GHSA-q38r-hcf4-gx69: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe
ghsa_unreviewed·2022-05-17·CVSS 3.3
CVE-2016-6224 [LOW] CWE-20 GHSA-q38r-hcf4-gx69: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
GHSA
GHSA-75gv-98wv-gmx4: ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and
ghsa_unreviewed·2022-05-17
CVE-2015-8946 [LOW] CWE-20 GHSA-75gv-98wv-gmx4: ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
OSV
CVE-2016-6224: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe
osv·2016-07-22·CVSS 3.3
CVE-2016-6224 [LOW] CVE-2016-6224: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
OSV
CVE-2015-8946: ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and
osv·2016-07-22·CVSS 3.3
CVE-2015-8946 [LOW] CVE-2015-8946: ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
bugzilla·2016-07-15·CVSS 3.3
CVE-2016-6224 [LOW] CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
A vulnerability was found in ecryptfs-setup-swap script that is provided by the upstream ecryptfs-utils project.
When GPT swap partitions are located on NVMe or MMC drives, ecryptfs-setup-swap fails to mark these swap partitions as "no-auto".
As a consequence, when using encrypted home directory with an NVMe or MMC drive, the swap is left unencrypted. There's also a usability issue in that users are erroneously prompted to enter a pass-phrase to unlock their swap partition at boot.
This vulnerability exists due to an incomplete fix for CVE-2015-8946
References:
http://seclists.org/oss-sec/2016/q3/52
Debian bug:
https://bugs.launchpad.net/ecryptfs
Bugzilla
CVE-2015-8946 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
bugzilla·2016-07-15·CVSS 3.3
CVE-2015-8946 [LOW] CVE-2015-8946 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
CVE-2015-8946 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
A vulnerability was found in ecryptfs-setup-swap script that is provided by the upstream ecryptfs-utils project.
On systems using systemd 211 or newer and GPT partitioning, the unencrypted swap partition was being automatically activated during boot and the encrypted swap was not used. This was due to ecryptfs-setup-swap not marking the swap partition as "no-auto", as defined by the Discoverable Partitions Spec.
References:
http://seclists.org/oss-sec/2016/q3/52
Debian bug:
https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/1447282
Fix:
https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/857
Discussion:
Created ecryptfs-utils tracking bugs for t
Bugzilla
CVE-2015-8946 CVE-2016-6224 ecryptfs-utils: various flaws [fedora-all]
bugzilla·2016-07-15·CVSS 3.3
CVE-2015-8946 [LOW] CVE-2015-8946 CVE-2016-6224 ecryptfs-utils: various flaws [fedora-all]
CVE-2015-8946 CVE-2016-6224 ecryptfs-utils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
http://www.openwall.com/lists/oss-security/2016/07/13/2http://www.openwall.com/lists/oss-security/2016/07/14/3http://www.ubuntu.com/usn/USN-3032-1https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/857https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/1447282http://www.openwall.com/lists/oss-security/2016/07/13/2http://www.openwall.com/lists/oss-security/2016/07/14/3http://www.ubuntu.com/usn/USN-3032-1https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/857https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/1447282
2016-07-22
Published