CVE-2016-6224
published 2016-07-22CVE-2016-6224: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2)…
PriorityP49low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.37%
29.9th percentile
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | <= 110 | — |
| ecryptfs | ecryptfs-utils | >= 0 < 111-0ubuntu1.1 | 111-0ubuntu1.1 |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
eCryptfs vulnerability
vendor_ubuntu·2016-07-14
CVE-2016-6224 eCryptfs vulnerability
Title: eCryptfs vulnerability
Summary: eCryptfs could be made to expose sensitive information.
It was discovered that eCryptfs incorrectly configured the encrypted swap
partition for certain drive types. An attacker could use this issue to discover
sensitive information.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
vendor_redhat·2016-07-06·CVSS 3.3
CVE-2016-6224 [LOW] CWE-200 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
Package: ecryptfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: ecryptfs-utils (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-6224: ecryptfs-utils - ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition ...
vendor_debian·2016·CVSS 3.3
CVE-2016-6224 [LOW] CVE-2016-6224: ecryptfs-utils - ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition ...
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-q38r-hcf4-gx69: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe
ghsa_unreviewed·2022-05-17·CVSS 3.3
CVE-2016-6224 [LOW] CWE-20 GHSA-q38r-hcf4-gx69: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
OSV
CVE-2016-6224: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe
osv·2016-07-22·CVSS 3.3
CVE-2016-6224 [LOW] CVE-2016-6224: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
bugzilla·2016-07-15·CVSS 3.3
CVE-2016-6224 [LOW] CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
A vulnerability was found in ecryptfs-setup-swap script that is provided by the upstream ecryptfs-utils project.
When GPT swap partitions are located on NVMe or MMC drives, ecryptfs-setup-swap fails to mark these swap partitions as "no-auto".
As a consequence, when using encrypted home directory with an NVMe or MMC drive, the swap is left unencrypted. There's also a usability issue in that users are erroneously prompted to enter a pass-phrase to unlock their swap partition at boot.
This vulnerability exists due to an incomplete fix for CVE-2015-8946
References:
http://seclists.org/oss-sec/2016/q3/52
Debian bug:
https://bugs.launchpad.net/ecryptfs
Bugzilla
CVE-2015-8946 CVE-2016-6224 ecryptfs-utils: various flaws [fedora-all]
bugzilla·2016-07-15·CVSS 3.3
CVE-2015-8946 [LOW] CVE-2015-8946 CVE-2016-6224 ecryptfs-utils: various flaws [fedora-all]
CVE-2015-8946 CVE-2016-6224 ecryptfs-utils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
http://www.openwall.com/lists/oss-security/2016/07/13/2http://www.openwall.com/lists/oss-security/2016/07/14/3http://www.ubuntu.com/usn/USN-3032-1https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/882https://bugs.launchpad.net/ecryptfs/+bug/1597154https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/1447282https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K5WWCVHDLRLZTYMXEIONYFHLYAXXLJW3/http://www.openwall.com/lists/oss-security/2016/07/13/2http://www.openwall.com/lists/oss-security/2016/07/14/3http://www.ubuntu.com/usn/USN-3032-1https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/882https://bugs.launchpad.net/ecryptfs/+bug/1597154https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/1447282https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K5WWCVHDLRLZTYMXEIONYFHLYAXXLJW3/
2016-07-22
Published