[CLSA-2026:1780411655] luksmeta: Fix of CVE-2025-11568
Type:
security
Severity:
Moderate
Release date:
2026-06-02 14:47:55 UTC
Description:
- CVE-2025-11568: fix data corruption in luksmeta when writing metadata larger than the gap between the LUKS1 header and encrypted data area; add upfront size validation in find_gap() and a hard-limit boundary check inside overlap() to prevent overrunning the gap and corrupting encrypted user data
CVEs fixed:
Updated packages:
  • libluksmeta-9-12.el9_2.tuxcare.els1.i686.rpm
    sha:0a5300cbe132cbb9a79892ac2c8fec9f31c5200ba9313b32a983d08a9e8e862d
  • libluksmeta-9-12.el9_2.tuxcare.els1.x86_64.rpm
    sha:94515d951f86e8c4bf52d0423c77cdc85e786d733ecdde8c368181871e15dfd2
  • libluksmeta-devel-9-12.el9_2.tuxcare.els1.i686.rpm
    sha:e642d1f3426091d80486ab86defbccf58f3fec7de86fd09d32921319b29e3cb7
  • libluksmeta-devel-9-12.el9_2.tuxcare.els1.x86_64.rpm
    sha:b8b439c8cf7afa09d7bb8ae1f29fc06fe089af402301dfecd836dee9c7105bbb
  • luksmeta-9-12.el9_2.tuxcare.els1.x86_64.rpm
    sha:35b24004b3becfcc49e443165b0db9da02b1926f7b7be112bdd194b88a790b85
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.