Data Corruption Vulnerability in Linux Unified Key Setup by Red Hat
CVE-2026-107565
5.1MEDIUM
What is CVE-2026-107565?
A flaw exists in the Linux Unified Key Setup (LUKS) system utilized by Red Hat, which can be exploited by a local attacker with administrative privileges. The vulnerability stems from improper boundary calculations and flawed overlap detection when writing metadata to LUKS devices. This flaw may allow an attacker to write new metadata entries beyond the allocated free space or overwrite existing records. Consequently, this could lead to corruption of stored encrypted payload data or existing metadata, making the affected data potentially inaccessible.
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Daniel Rond for reporting this issue.