Candidate: CVE-2016-6224 PublicDate: 2016-07-22 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6224 https://ubuntu.com/security/notices/USN-3032-1 Description: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946. Ubuntu-Description: Notes: tyhicks> This issue only occurs when systemd and GPT partitioning is in use on an NVMe or MMC drive Bugs: https://launchpad.net/bugs/1597154 Priority: medium Discovered-by: Assigned-to: tyhicks CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N [3.3 LOW] Patches_ecryptfs-utils: upstream: https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/859 upstream_ecryptfs-utils: pending (112) precise_ecryptfs-utils: not-affected (systemd not in use) trusty_ecryptfs-utils: not-affected (systemd not in use) trusty/esm_ecryptfs-utils: not-affected (systemd not in use) vivid/stable-phone-overlay_ecryptfs-utils: DNE vivid/ubuntu-core_ecryptfs-utils: DNE wily_ecryptfs-utils: released (108-0ubuntu1.2) xenial_ecryptfs-utils: released (111-0ubuntu1.1) esm-infra/xenial_ecryptfs-utils: released (111-0ubuntu1.1) devel_ecryptfs-utils: released (111-0ubuntu2)