Vulnerabilities in LUKS2 disk encryption for confidential VMs
blog.trailofbits.com·1d
Flag this post

Trail of Bits is disclosing vulnerabilities in eight different confidential computing systems that use Linux Unified Key Setup version 2 (LUKS2) for disk encryption. Using these vulnerabilities, a malicious actor with access to storage disks can extract all confidential data stored on that disk and can modify the contents of the disk arbitrarily. The vulnerabilities are caused by malleable metadata headers that allow an attacker to trick a trusted execution environment guest into encrypting secret data with a null cipher. The following CVEs are associated with this disclosure:

This is a coordinated disclosure; we have notified the following projects…

Similar Posts

Loading similar posts...