FEK is encrypted with FNEK and stored in file header
Bug #342128 reported by
Tyler Hicks
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
eCryptfs |
Fix Released
|
Critical
|
Tyler Hicks | ||
linux (Ubuntu) |
Fix Released
|
Critical
|
Tim Gardner |
Bug Description
The file encryption key (FEK) is being encrypted with the file encryption key encryption key (FEKEK) and stored in the file header (correct behavior). The FEK is also being encrypted with the filename encryption key (FNEK) and stored in the file header (incorrect behavior). This results in either the FEKEK or the FNEK being capable of decrypting the FEK and eventually the file contents.
Related branches
Changed in ecryptfs: | |
status: | In Progress → Fix Committed |
status: | Fix Committed → In Progress |
Changed in linux: | |
importance: | High → Critical |
Changed in ecryptfs: | |
importance: | High → Critical |
To post a comment you must log in.
This is a tested patch that applies to 2.6.29-rc8.