Logo
vulnerabilityCVE-2025-4382
Name
CVE-2025-4382
Source
NVD ( link)Debian ( link)
Description
A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker with physical access can corrupt the underlying filesystem superblock, GRUB will fail to locate a valid filesystem and enter rescue mode. At this point, the disk is already decrypted, and the decryption key remains loaded in system memory. This scenario may allow an attacker with physical access to access the unencrypted data without any further authentication, thereby compromising data confidentiality. Furthermore, the ability to force this state through filesystem corruption also presents a data integrity concern.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
grub
Exploitable

Vulnerability Ratings#


5.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.12
Exploitable
buildroot
master
2.14
Not Affected
openwrt
master
2.12-r1
Exploitable
openwrt
openwrt-25.12
2.12-r1
Exploitable
yocto
master
2.14
Not Affected
yocto
scarthgap
2.12
Exploitable