Junglewise Threat Intelligence

CVE-2025-11568: Latchset luksmeta data corruption in LUKS1 partitions

CVE-2025-11568 · Severity: medium · CVSS 4.4 · Published 2025-10-15

Technologies: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8. Vendors: Red Hat.

Executive brief

A data corruption vulnerability exists in the luksmeta utility, which is used to store metadata in encrypted disk headers. An attacker with high-level system permissions can cause the utility to overwrite and permanently destroy a user's encrypted data by providing an excessively large amount of metadata. This results in permanent data loss on systems using the older LUKS1 encryption format.

Technical details

A data corruption vulnerability (CWE-1284) exists in the luksmeta utility when interacting with the LUKS1 disk encryption format. The root cause is a failure to correctly validate available header space before writing metadata. A local attacker with high privileges (PR:H) can exploit this by writing a large volume of metadata, which overflows the designated header area and overwrites the actual encrypted user data. This leads to irreversible data loss. The issue is specific to LUKS1; LUKS2 and other formats are unaffected. Patches have been released by Red Hat for RHEL 8 and RHEL 10.

Affected products

  • Latchset luksmeta All versions used with LUKS1 format
  • Red Hat Red Hat Enterprise Linux 8 luksmeta-9-4.el8_10.1
  • Red Hat Red Hat Enterprise Linux 10 luksmeta-10-1.el10

Timeline

  • 2025-10-15: disclosed: Initial vulnerability report and NVD publication
  • 2025-12-11: patched: Red Hat released security update RHSA-2025:23086 for RHEL 8
  • 2026-05-19: patched: Red Hat released security update RHSA-2026:18421 for RHEL 10

References

Related threats