CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
Percentile
5.1%
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap
partition from activating during boot when using GPT partitioning on a (1)
NVMe or (2) MMC drive, which allows local users to obtain sensitive
information via unspecified vectors. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2015-8946.
Author | Note |
---|---|
tyhicks | This issue only occurs when systemd and GPT partitioning is in use on an NVMe or MMC drive |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 15.10 | noarch | ecryptfs-utils | < 108-0ubuntu1.2 | UNKNOWN |
ubuntu | 16.04 | noarch | ecryptfs-utils | < 111-0ubuntu1.1 | UNKNOWN |
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
Percentile
5.1%