Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-36476— `calamares-nixos-extensions` LUKS keyfile exposure

Quick assessment

Affected
NixOS calamares-nixos-extensions
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Calamares是Calamares团队的一款通用安装程序框架。 Calamares calamares-nixos-extensions 0.3.12及之前版本存在信息泄露漏洞,该漏洞源于用户通过图形 calamares 安装程序安装 NixOS时,在非 UEFI 系统上使用未加密的/boot或使用与/不同的 LUKS 分区,可以将他们的 LUKS 密钥文件/boot作为明文CPIO 存档附加到他们的 NixOS initrd 中。

CVSS 7.9 · High EPSS 0.26% · P18

Possible ATT&CK Techniques 1 AI

T1552.004 · Private Keys
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-36476

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
`calamares-nixos-extensions` LUKS keyfile exposure
Source: CVE Program / CVE List V5
Vulnerability Description
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions version 0.3.12 and prior who installed NixOS through the graphical calamares installer, with an unencrypted `/boot`, on either non-UEFI systems or with a LUKS partition different from `/` have their LUKS key file in `/boot` as a plaintext CPIO archive attached to their NixOS initrd. A patch is available and anticipated to be part of version 0.3.13 to backport to NixOS 22.11, 23.05, and unstable channels. Expert users who have a copy of their data may, as a workaround, re-encrypt the LUKS partition(s) themselves.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
calamares-nixos-extensions 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Calamares是Calamares团队的一款通用安装程序框架。 Calamares calamares-nixos-extensions 0.3.12及之前版本存在信息泄露漏洞,该漏洞源于用户通过图形 calamares 安装程序安装 NixOS时,在非 UEFI 系统上使用未加密的/boot或使用与/不同的 LUKS 分区,可以将他们的 LUKS 密钥文件/boot作为明文CPIO 存档附加到他们的 NixOS initrd 中。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
NixOS calamares-nixos-extensions <= 0.3.12 -

II. Public POCs for CVE-2023-36476

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-36476

登录查看更多情报信息。

Patches & Fixes for CVE-2023-36476 (1)

Vendor Advisories for CVE-2023-36476 (1)

Other References for CVE-2023-36476 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-36476

No comments yet


Leave a comment