Data Corruption Vulnerability in Linux Unified Key Setup by Red Hat
CVE-2026-107565

5.1MEDIUM

What is CVE-2026-107565?

A flaw exists in the Linux Unified Key Setup (LUKS) system utilized by Red Hat, which can be exploited by a local attacker with administrative privileges. The vulnerability stems from improper boundary calculations and flawed overlap detection when writing metadata to LUKS devices. This flaw may allow an attacker to write new metadata entries beyond the allocated free space or overwrite existing records. Consequently, this could lead to corruption of stored encrypted payload data or existing metadata, making the affected data potentially inaccessible.

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Daniel Rond for reporting this issue.
.