CVE-2019-13178 describes a race condition in Calamares versions 3.1 through 3.2.10, specifically within the modules/luksbootkeyfile/main.py component. This vulnerability arises from a timing issue between the creation of a LUKS encryption keyfile and the subsequent application of secure permissions. Rated with a CVSS score of 8.1 (HIGH), it presents a high-impact threat with potential for complete compromise (confidentiality, integrity, availability) via a network-based attack, though it requires high attack complexity. Currently, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1, <= 3.2.10CPE matchmatch criteria | cpe:2.3:a:calamares:calamares:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.