udisks Missing Authorization Vulnerability Allows Unauthorized Backup of LUKS Encryption Headers

Vulnerability

A vulnerability exists in the udisks storage management daemon, allowing unprivileged users to unauthorizedly back up LUKS encryption headers. This issue arises because a privileged D-Bus method intended for exporting encryption metadata lacks a proper policy check. Consequently, sensitive cryptographic metadata can be accessed and written to locations controlled by the attacker, undermining the confidentiality of encrypted storage volumes.

Impact

Exploitation of this vulnerability leads to the unauthorized disclosure of LUKS encryption metadata, which could facilitate offline password-cracking or cryptographic analysis attacks.

Reproduction

The vulnerability can be reproduced by an unprivileged local user who invokes the 'org.freedesktop.UDisks2.Encrypted.HeaderBackup' D-Bus method. This action triggers the udisks daemon to export LUKS headers and keyslot metadata to a file path specified by the user, without requiring authentication or user interaction.

Added: Feb 25, 2026, 11:22 AM
Updated: Feb 25, 2026, 11:22 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.8
exploitability
3.2
remediation
0.0
relevance
3.5
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.