VYPR
Medium severity6.5NVD Advisory· Published Feb 8, 2023· Updated Jun 17, 2026

CVE-2023-0751

CVE-2023-0751

Description

When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key file allowing trivial recovery of the master key.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

20
  • FreeBSD/FreeBSD19 versions
    cpe:2.3:o:freebsd:freebsd:12.3:-:*:*:*:*:*:*+ 18 more
    • cpe:2.3:o:freebsd:freebsd:12.3:-:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:12.3:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:12.3:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:12.3:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:12.3:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:12.3:p5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:12.4:-:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:12.4:rc2-p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:12.4:rc2-p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:-:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:b1-p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:b2-p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:p5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.1:rc1-p1:*:*:*:*:*:*
    • (no CPE)range: 13.1-RELEASE
  • FreeBSD/gelillm-create

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.