CVE-2016-8637
published 2018-08-01CVE-2016-8637: A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used…
PriorityP433high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
22.9th percentile
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dracut | < dracut 044+189-1 (bookworm) | dracut 044+189-1 (bookworm) |
| dracut_project | dracut | < 045 | 045 |
| dracut_project | dracut | >= 0 < 044+189-1 | 044+189-1 |
| dracut_project | dracut | >= 0 < 044+189-1 | 044+189-1 |
| dracut_project | dracut | >= 0 < 044+189-1 | 044+189-1 |
| dracut_project | dracut | >= 0 < 044+189-1 | 044+189-1 |
| the_dracut_project | dracut | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dracut: Local information disclosure of initramfs when early cpio is used
vendor_redhat·2016-11-07·CVSS 5.0
CVE-2016-8637 [MEDIUM] CWE-732 dracut: Local information disclosure of initramfs when early cpio is used
dracut: Local information disclosure of initramfs when early cpio is used
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
Package: dracut (Red Hat Enterprise Linux 6) - Not affected
Package: dracut (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-8637: dracut - A local information disclosure issue was found in dracut before 045 when generat...
vendor_debian·2016·CVSS 5.0
CVE-2016-8637 [MEDIUM] CVE-2016-8637: dracut - A local information disclosure issue was found in dracut before 045 when generat...
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
Scope: local
bookworm: resolved (fixed in 044+189-1)
bullseye: resolved (fixed in 044+189-1)
forky: resolved (fixed in 044+189-1)
sid: resolved (fixed in 044+189-1)
trixie: resolved (fixed in 044+189-1)
GHSA
GHSA-wf9g-696p-j466: A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio'
ghsa_unreviewed·2022-05-13
CVE-2016-8637 [HIGH] CWE-200 GHSA-wf9g-696p-j466: A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio'
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
OSV
CVE-2016-8637: A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio'
osv·2018-08-01·CVSS 7.8
CVE-2016-8637 [HIGH] CVE-2016-8637: A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio'
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container
bugzilla·2019-07-03·CVSS 2.1
CVE-2019-13179 [LOW] CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container
CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container
Calamares through 3.2.4 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.
Reference:
https://github.com/calamares/calamares/issues/1191
Discussion:
Created calamares tracking bugs for this issue:
Affects: fedora-all [bug 1726543]
---
This CVE only affects the Debian mkinitramfs (initramfs-tools), which is not used in the Fedora configuration for Calamares. The underlying tool is also not shipped at all by Fedora.
Bugzilla
CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container [fedora-all]
bugzilla·2019-07-03·CVSS 7.5
CVE-2019-13179 [HIGH] CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container [fedora-all]
CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used
bugzilla·2016-11-10·CVSS 5.0
CVE-2016-8637 [MEDIUM] CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used
CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used
Hi,
Please note that RHEL 7.3 and RHEL 7.4 are not affected by this bug (0396-dracut-only-use-one-tmpdir.patch fixes this flaw, perhaps accidentally). RHEL 7.0, RHEL 7.1 and RHEL 7.2 are affected.
The Product Security team has rated this flaw as having a moderate security impact. So there won't be any 7.0.z / 7.1.z / 7.2.z security errata (RHSA) for this bug.
Bugzilla
CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used [fedora-all]
bugzilla·2016-11-07·CVSS 5.0
CVE-2016-8637 [MEDIUM] CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used [fedora-all]
CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used
bugzilla·2016-11-04·CVSS 5.0
CVE-2016-8637 [MEDIUM] CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used
CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used
A local information disclosure issue was found in dracut when generating initramfs images with world-readable permissions when "early cpio" is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
Vulnerable code:
if [[ $create_early_cpio = yes ]]; then
echo 1 > "$early_cpio_dir/d/early_cpio"
# The microcode blob is _before_ the initramfs blob, not after
(cd "$early_cpio_dir/d"; find . -print0 | cpio --null $cpio_owner_root -H newc -o --quiet > $outfile)
fi
if ! ( umask 077; cd "$initdir"; find . -print0 | cpio --null $cpio_owner_root -H newc -o --quiet | \
$compress >> "$outfile"; ); then
http://seclists.org/oss-sec/2016/q4/352http://www.securityfocus.com/bid/94128https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4http://seclists.org/oss-sec/2016/q4/352http://www.securityfocus.com/bid/94128https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4
2018-08-01
Published