CVE-2026-107565

NameCVE-2026-107565
DescriptionA flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata to a Linux Unified Key Setup (LUKS) device. Due to incorrect boundary calculations and flawed overlap detection, new metadata entries can be written beyond available free space or over existing records. This issue can corrupt stored encrypted payload data or existing metadata, potentially rendering the affected data inaccessible.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
luksmeta (PTS)bookworm9-4+deb12u1vulnerable
trixie9-4+deb13u1vulnerable
forky, sid10-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
luksmetasource(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2547930
check for upstream details

Search for package or bug name: Reporting problems