PatchSiren cyber security CVE debrief
CVE-2025-11568 Latchset CVE debrief
A data corruption vulnerability exists in the luksmeta utility when used with LUKS1 disk encryption format. The utility fails to validate available space before writing metadata, allowing an attacker with sufficient permissions to overwrite and permanently corrupt encrypted user data by writing excessive metadata. LUKS2 and other formats are unaffected.
- Vendor
- Latchset
- Product
- luksmeta utility
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-10-15
- Original CVE updated
- 2026-09-01
- Advisory published
- 2025-10-15
- Advisory updated
- 2026-09-01
Who should care
System administrators managing LUKS1-encrypted storage, security teams responsible for full-disk encryption deployments, and organizations using luksmeta for key escrow or metadata management on encrypted volumes.
Technical summary
The luksmeta utility, used for storing metadata in LUKS headers, contains a validation flaw when operating on LUKS1-formatted devices. The utility does not properly check available space before writing metadata, enabling a privileged attacker to write metadata that overflows its allocated region and overwrites adjacent encrypted data. This results in irreversible data corruption. The vulnerability is confined to LUKS1; LUKS2's different header structure prevents this issue. CVSS 3.1 score of 4.4 (Medium) reflects local attack vector, high privileges required, and high impact to integrity with no confidentiality or availability impact per the scoring vector.
Defensive priority
medium
Recommended defensive actions
- Apply vendor patches from Red Hat security advisories when available
- Upgrade luksmeta to patched version incorporating PR #16 fixes
- Restrict access to luksmeta utility to authorized administrative users only
- Monitor for unusual metadata write operations on LUKS1-encrypted devices
- Consider migrating critical LUKS1 volumes to LUKS2 format which is unaffected by this vulnerability
- Review backup and recovery procedures for encrypted data protection
Evidence notes
Vulnerability affects luksmeta utility specifically with LUKS1 format. Root cause is insufficient space validation during metadata write operations. Issue tracked in Red Hat Bugzilla 2404244. Fix implemented via GitHub pull request #16 in latchset/luksmeta repository.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-11568 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-11568
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-11568 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-11568
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2025:23086
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:18421
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:18824
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2025-11568
-
Source reference
Unverified legacy reference
URL: https://github.com/latchset/luksmeta/pull/16
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.