A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.
References
Configurations
History
No history.
Information
Published : 2026-02-25 11:16
Updated : 2026-03-25 19:16
NVD link : CVE-2026-26103
Mitre link : CVE-2026-26103
CVE.ORG link : CVE-2026-26103
JSON object : View
Products Affected
freedesktop
- udisks
redhat
- enterprise_linux
CWE
CWE-862
Missing Authorization
