Medium severity6.5NVD Advisory· Published Feb 8, 2023· Updated Jun 17, 2026
CVE-2023-0751
CVE-2023-0751
Description
When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key file allowing trivial recovery of the master key.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20cpe:2.3:o:freebsd:freebsd:12.3:-:*:*:*:*:*:*+ 18 more
- cpe:2.3:o:freebsd:freebsd:12.3:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.3:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.3:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.3:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.3:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.3:p5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.4:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.4:rc2-p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:12.4:rc2-p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:b1-p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:b2-p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:p5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.1:rc1-p1:*:*:*:*:*:*
- (no CPE)range: 13.1-RELEASE
Patches
Vulnerability mechanics
References
2- security.freebsd.org/advisories/FreeBSD-SA-23:01.geli.ascnvdMitigationPatchVendor Advisory
- security.netapp.com/advisory/ntap-20230316-0004/nvd
News mentions
0No linked articles in our index yet.