CVE-2023-0751 - CVE House
Back to Database
Status published Unknown CVE-2023-0751

GELI silently omits the keyfile if read from stdin

Vulnerability Description

When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key file allowing trivial recovery of the master key.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-0751

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

FreeBSD
Vulnerable Versions:
13.1-RELEASE, 12.4-RELEASE, 12.3-RELEASE

Timeline

Official Publish: February 8th, 2023
Last Modified: March 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)