Executive brief
VeraCrypt is a disk encryption tool that protects sensitive data by deriving encryption keys from passwords using computationally expensive functions. Non-default builds compiled with WolfCrypt routing incorrectly bypassed password iteration settings, allowing attackers to perform offline password guesses far faster than intended. Volumes encrypted with affected builds can be cracked in substantially less time, compromising the confidentiality of all encrypted data.
Technical details
The vulnerability affects non-default VeraCrypt builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND options. The issue is a logic error in src/Crypto/wolfCrypt.c where SHA-256 and SHA-512 volume-header key derivation functions discard the configured iteration count and use wolfSSL's HKDF (HMAC-based Key Derivation Function) instead of the intended PBKDF2-HMAC algorithm. This means that changing the PIM (Personal Iteration Multiplier) or iteration count provides no increase in key derivation cost. An attacker with access to an affected container or volume header can perform offline password attacks with reduced computational burden. Official precompiled VeraCrypt binaries and standard distribution packages use the correct PBKDF2 backend and are unaffected. The fix is available in version 1.26.29.
Affected products
- VeraCrypt VeraCrypt prior to 1.26.29 (only non-default builds with WOLFCRYPT=1 and WOLFCRYPT_BACKEND)
Timeline
- 2026-08-21: disclosed
- 2026-06-09: patched: Version 1.26.29 released with fix