Executive brief
A data corruption vulnerability exists in the luksmeta utility, which is used to store metadata in encrypted disk headers. An attacker with high-level system permissions can cause the utility to overwrite and permanently destroy a user's encrypted data by providing an excessively large amount of metadata. This results in permanent data loss on systems using the older LUKS1 encryption format.
Technical details
A data corruption vulnerability (CWE-1284) exists in the luksmeta utility when interacting with the LUKS1 disk encryption format. The root cause is a failure to correctly validate available header space before writing metadata. A local attacker with high privileges (PR:H) can exploit this by writing a large volume of metadata, which overflows the designated header area and overwrites the actual encrypted user data. This leads to irreversible data loss. The issue is specific to LUKS1; LUKS2 and other formats are unaffected. Patches have been released by Red Hat for RHEL 8 and RHEL 10.
Affected products
- Latchset luksmeta All versions used with LUKS1 format
- Red Hat Red Hat Enterprise Linux 8 luksmeta-9-4.el8_10.1
- Red Hat Red Hat Enterprise Linux 10 luksmeta-10-1.el10
Timeline
- 2025-10-15: disclosed: Initial vulnerability report and NVD publication
- 2025-12-11: patched: Red Hat released security update RHSA-2025:23086 for RHEL 8
- 2026-05-19: patched: Red Hat released security update RHSA-2026:18421 for RHEL 10