MEDIUM
GELI silently omits the keyfile if read from stdin
Published Feb 8, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.64%
Description
When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key file allowing trivial recovery of the master key.
Affected products
-
- Version 12.3-RELEASEStatusaffectedConstraints<12.3-RELEASE-p11
- Version 12.4-RELEASEStatusaffectedConstraints<12.4-RELEASE-p1
- Version 13.1-RELEASEStatusaffectedConstraints<13.1-RELEASE-p6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
OR
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.4
- 12.4
- 12.4
- 13.1
- 13.1
- 13.1
- 13.1
- 13.1
- 13.1
- 13.1
- 13.1
- 13.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12769 Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-23:01.geli.asc MitigationPatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20230316-0004/
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12769 | Advisory | |
| https://security.FreeBSD.org/advisories/FreeBSD-SA-23:01.geli.asc | MitigationPatchVendor Advisory | |
| https://security.netapp.com/advisory/ntap-20230316-0004/ |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner freebsd
Published Feb 8, 2023
Updated Mar 25, 2025
Reserved Feb 8, 2023
Link CVE-2023-0751
CISA Vulnrichment
Updated Mar 25, 2025
ENISA EUVD
EUVD-2023-12769 Assigner freebsd
Published Feb 8, 2023
Updated Mar 25, 2025
Exploited since n/a
Link EUVD-2023-12769