A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker with the necessary permissions can exploit this flaw by writing a large amount of metadata to an encrypted device. The utility fails to correctly validate the available space, causing the metadata to overwrite and corrupt the user's encrypted data. This action leads to a permanent loss of the stored information. Devices using the LUKS formats other than LUKS1 are not affected by this issue.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libluksmeta-develUpgrade luksmetaUpgrade libluksmeta | Dec 15, 2025 | Dec 11, 2025 |
| Debian | — | Upgrade luksmeta | Jan 12, 2026 | Jan 12, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Feb 18, 2026 |
| Oracle_linux | — | Upgrade libluksmetaUpgrade libluksmeta-develUpgrade luksmeta | Dec 12, 2025 | Oct 14, 2025 |
| Redhat_linux | — | Upgrade libluksmeta-debuginfoUpgrade luksmetaUpgrade luksmeta-debugsourceUpgrade libluksmetaUpgrade libluksmeta-develUpgrade luksmeta-debuginfoNo solution exists | Dec 12, 2025 | Oct 14, 2025 |
| Rocky_linux | — | Upgrade luksmeta-debugsourceUpgrade luksmeta-debuginfoUpgrade libluksmeta-develUpgrade libluksmeta-debuginfoUpgrade luksmetaUpgrade libluksmeta | Feb 5, 2026 | Dec 13, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub