Comment 4 for bug 1835095

Revision history for this message
Thomas Ward (teward) wrote :

The following CVE IDs have been issued for Calamares in this instance by MITRE, IDs were requested via the CVE form:

CVE-2019-13178 was assigned for the race condition that Seth Arnold identified in https://github.com/calamares/calamares/issues/1190 regarding unsafe UMask and file permissions during creation of the keyfile.

CVE-2019-13179 was assigned for the improper handling of the LUKS encryption keyfile from /crypto_keyfile.bin to /boot in a globally readable initramfs issue for which upstream issue https://github.com/calamares/calamares/issues/1191 was created.