Listen to this Post
How the mentioned CVE works:
The vulnerability exists in cryptsetup versions prior to 2.8.1. LUKS2 volumes contain a header with metadata, including keyslots that store the master key, encrypted by a user’s passphrase. This keyslot encryption algorithm is specified in the header. An attacker can craft a malicious LUKS2 volume where the keyslot uses the `cipher_null-ecb` algorithm, meaning no encryption is applied. When a victim’s system runs `cryptsetup open` on this volume, it successfully “decrypts” the keyslot using any passphrase because the null cipher requires no key. The system then uses the attacker-provided master key for the disk, allowing the attacker to read all subsequent “encrypted” writes and pre-load plaintext data that the guest trusts.
DailyCVE Form:
Platform: Linux cryptsetup
Version: < 2.8.1
Vulnerability: Cryptographic Bypass
Severity: Critical
date: 2021
Prediction: Patched 2021
What Undercode Say:
Creating a malicious LUKS2 volume with null cipher cryptsetup luksFormat --type luks2 --cipher cipher_null-ecb /dev/malicious_device Victim command, succeeds with any passphrase cryptsetup open /dev/attacker_volume my_volume
How Exploit:
Attacker creates a specially crafted LUKS2 disk image where the keyslot encryption algorithm is set to cipher_null-ecb. This malicious disk is then presented to a target confidential computing guest VM. When the guest attempts to unlock the disk, the operation succeeds regardless of the passphrase provided. The guest proceeds to write its confidential data to the disk, but this data is either written in plaintext or encrypted with a key known to the attacker.
Protection from this CVE:
Upgrade to cryptsetup 2.8.1 or later. For Constellation users, upgrade to v2.24.0 or later, which implements detached header verification, ensuring the LUKS header is validated before being used to open a device.
Impact:
Complete loss of data confidentiality for the guest VM. The host or storage provider can decrypt all data written by the guest to the persistent volume, breaching the security guarantees of confidential computing.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

