CVE-2026-107565
Received Received - Intake

LUKS Metadata Corruption via Boundary Miscalculation

Vulnerability report for CVE-2026-107565, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: redhat-SADP

Description

A flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata to a Linux Unified Key Setup (LUKS) device. Due to incorrect boundary calculations and flawed overlap detection, new metadata entries can be written beyond available free space or over existing records. This issue can corrupt stored encrypted payload data or existing metadata, potentially rendering the affected data inaccessible.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat luksmeta *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the luksmeta tool used for managing LUKS1 encrypted disk metadata. It involves incorrect boundary calculations and flawed overlap detection when saving metadata to a LUKS device. An attacker with root access can write metadata entries beyond free space or over existing records, causing data corruption. LUKS2 is not affected.

Detection Guidance

Detecting this vulnerability requires checking if your system uses LUKS1 format and inspecting luksmeta tool versions. Run 'sudo luksmeta show' to verify LUKS1 usage and check for metadata corruption. Inspect luksmeta package version with 'rpm -q luksmeta' or 'dpkg -l luksmeta' depending on your distribution.

Impact Analysis

The impact is limited to data corruption. Stored encrypted payload data or existing metadata may become inaccessible. Exploitation requires root-level write access to a LUKS1-formatted device and does not grant additional privileges or disclose data.

Compliance Impact

This vulnerability primarily causes data corruption in LUKS1 encrypted devices, potentially making stored data inaccessible. It does not grant unauthorized access or expose sensitive information, which are key concerns for GDPR and HIPAA. However, data corruption could lead to compliance issues if critical data becomes unavailable or integrity is compromised.

Mitigation Strategies

Migrate from LUKS1 to LUKS2 format using 'cryptsetup convert --type luks2 /dev/device'. If migration is not possible, restrict root access to LUKS devices and monitor for metadata corruption. No official patches are available per Red Hat.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107565. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart