CVE-2025-11568
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-15

Last updated on: 2026-03-19

Assigner: Red Hat, Inc.

Description
A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker with the necessary permissions can exploit this flaw by writing a large amount of metadata to an encrypted device. The utility fails to correctly validate the available space, causing the metadata to overwrite and corrupt the user's encrypted data. This action leads to a permanent loss of the stored information. Devices using the LUKS formats other than LUKS1 are not affected by this issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-15
Last Modified
2026-03-19
Generated
2026-05-07
AI Q&A
2025-10-15
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
redhat luksmeta *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a data corruption issue in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker who has the necessary permissions can exploit this flaw by writing a large amount of metadata to an encrypted device. The utility does not properly check if there is enough space, causing the metadata to overwrite and corrupt the user's encrypted data, resulting in permanent data loss. Other LUKS formats besides LUKS1 are not affected.


How can this vulnerability impact me? :

If exploited, this vulnerability can cause permanent loss of encrypted data on devices using the LUKS1 format. An attacker with the required permissions can corrupt the stored information by overwriting it with excessive metadata, leading to data corruption and loss.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart