Ubuntu Security Flaw Lets Attackers Bypass Full Disk Encryption
Cybersecurity researchers have discovered a “critical” security vulnerability on Linux that can give attackers full system access — even on devices using full disk encryption. A report published by ERNW demonstrates the exploit on Ubuntu 25.04 and Fedora 42, though not all Linux distributions are affected, such as OpenSUSE Tumbleweed. So how does it work? Attackers with physical access to a Linux system can access a debug shell simply by entering the wrong decryption password several times in a row. On Ubuntu, they hit esc at the password prompt, punch in a few key combos, and bam: debug shell appears. […]
You're reading Ubuntu Security Flaw Lets Attackers Bypass Full Disk Encryption, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.