VYPR
High severity7.8OSV Advisory· Published Aug 16, 2024· Updated Jun 17, 2026

CVE-2024-43378

CVE-2024-43378

Description

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning to create a setup where the system was booted via legacy BIOS rather than UEFI; some disk partitions are encrypted; but the partitions containing either / or /boot are unencrypted; have their LUKS disk encryption key file in plain text either in /crypto_keyfile.bin, or in a CPIO archive attached to their NixOS initrd. nixos-install is not affected, nor are UEFI installations, nor was the default automatic partitioning configuration on legacy BIOS systems. The problem has been fixed in calamares-nixos-extensions 0.3.17, which was included in NixOS. The current installer images for the NixOS 24.05 and unstable (24.11) channels are unaffected. The fix reached 24.05 at 2024-08-13 20:06:59 UTC, and unstable at 2024-08-15 09:00:20 UTC. Installer images downloaded before those times may be vulnerable. The best solution for affected users is probably to back up their data and do a complete reinstallation. However, the mitigation procedure in GHSA-3rvf-24q2-24ww should work solely for the case where / is encrypted but /boot is not. If / is unencrypted, then the /crypto_keyfile.bin file will need to be deleted in addition to the remediation steps in the previous advisory. This issue is a partial regression of CVE-2023-36476 / GHSA-3rvf-24q2-24ww, which was more severe as it applied to the default configuration on BIOS systems.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • 0.0.1, 0.0.2, 0.0.3, …+ 1 more
    • (no CPE)range: 0.0.1, 0.0.2, 0.0.3, …
    • (no CPE)range: before 0.3.17
  • Nixos/Nixosllm-fuzzy
    Range: Installer images downloaded before 2024-08-13 20:06:59 UTC (24.05 channel) or 2024-08-15 09:00:20 UTC (unstable channel)

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.