Executive brief
A vulnerability in the disk encryption unlock process allows an individual with physical access to a computer to bypass security and gain administrative control. By repeatedly entering an incorrect password or holding down a specific key during the boot process, an attacker can drop into a recovery shell. This allows them to potentially steal data from unencrypted partitions, modify system files, or perform a denial-of-service attack by deleting disk contents.
Technical details
A vulnerability exists in the 'cryptroot' initramfs script within the cryptsetup package (specifically Debian versions 2:1.7.3-2 and earlier). The script fails to securely handle cases where the maximum number of password attempts (typically 3) is exceeded; instead of halting, it allows the boot sequence to continue, eventually dropping the user into a BusyBox root shell. An attacker with physical access (or console access in cloud environments) can exploit this by holding the Enter key for approximately 70-93 seconds to trigger multiple failed attempts. Once in the initramfs shell, the attacker can access unencrypted partitions, exfiltrate data if networking is available, or modify the boot partition to facilitate further privilege escalation. The issue has been addressed in later versions of the cryptsetup scripts and can be mitigated by configuring bootloader passwords or disabling the shell on failure.
Affected products
- Debian cryptsetup 2:1.7.3-2 and earlier
- Red Hat Fedora 24
Timeline
- 2016-11-11: disclosed: Disclosed at DeepSec 2016 conference
- 2016-11-14: advisory: Public advisory released by researchers
- 2017-01-23: advisory: NVD publication date
References
- http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html
- http://www.openwall.com/lists/oss-security/2016/11/14/13
- http://www.openwall.com/lists/oss-security/2016/11/15/1
- http://www.openwall.com/lists/oss-security/2016/11/15/4
- http://www.openwall.com/lists/oss-security/2016/11/16/6
- http://www.securityfocus.com/bid/94315
- https://gitlab.com/cryptsetup/cryptsetup/commit/ef8a7d82d8d3716ae9b58179590f7908981fa0cb