PatchSiren

Latchset CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Latchset CVE published 2025-10-15

CVE-2025-11568

A data corruption vulnerability exists in the luksmeta utility when used with LUKS1 disk encryption format. The utility fails to validate available space before writing metadata, allowing an attacker with sufficient permissions to overwrite and permanently corrupt encrypted user data by writing excessive metadata. LUKS2 and other formats are unaffected.