Public bug reported:

Recent changes to the dhcpd hook shipped with dhcpdinitramfs-tools 
0.142ubuntu23 (noble-dev) copy the host /etc/passwd into the initramfs-image:
https://git.launchpad.net/ubuntu/+source/initramfs-tools/commit/hooks/dhcpcd?h=applied/ubuntu/noble&id=73c865b9d234087d977d7baa20852639746567fd

This has multiple problems:
 * The passwd file is copied without checking if the dhcpcd user actually 
exists (which is created by dhcpcd package, but only dhcpcd-base is installed 
via dependencies)
 * The change breaks dropbear-initramfs because the passwd file contains a root 
user with a non existing home directory
 * leaking user information into initramfs (which may or may not be a problem 
on fully encrypted systems)

** Affects: initramfs-tools (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2059739

Title:
  initramfs-tools 0.142ubuntu23 copies host /etc/passwd into initramfs

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/2059739/+subscriptions


-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to