CVE-2020-11932
Subiquity server installer logged LUKS full disk encryption password
- Published
- May 13, 2020
- Updated
- Sep 16, 2024
- Assigning CNA
- canonical
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NLow · next 30 days
- Percentile
- 46.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.
Sources
2- CVE-2020-11932Exploit
Proof-of-concept exploit for CVE-2020-11932, a double-free vulnerability in WhatsApp GIF processing, enabling remote code execution via crafted .gif file.
- CVE-2020-11932Exploit
Double-Free BUG in WhatsApp exploit poc.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.