Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1356828 - (CVE-2016-6224) CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encry...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20160706,repor...
: Security
Depends On: 1356826
Blocks: 1356829
  Show dependency treegraph
 
Reported: 2016-07-15 02:48 EDT by Andrej Nemec
Modified: 2016-11-08 04:51 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-11-08 04:51:48 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Andrej Nemec 2016-07-15 02:48:45 EDT
A vulnerability was found in ecryptfs-setup-swap script that is provided by the upstream ecryptfs-utils project.

When GPT swap partitions are located on NVMe or MMC drives, ecryptfs-setup-swap fails to mark these swap partitions as "no-auto".

As a consequence, when using encrypted home directory with an NVMe or MMC drive, the swap is left unencrypted. There's also a usability issue in that users are erroneously prompted to enter a pass-phrase to unlock their swap partition at boot.

This vulnerability exists due to an incomplete fix for CVE-2015-8946

References:

http://seclists.org/oss-sec/2016/q3/52

Debian bug:

https://bugs.launchpad.net/ecryptfs/+bug/1597154

Fix:

https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/882
Comment 1 Andrej Nemec 2016-07-15 02:49:48 EDT
Created ecryptfs-utils tracking bugs for this issue:

Affects: fedora-all [bug 1356826]

Note You need to log in before you can comment on or make changes to this bug.