📖 ~4 min read • Source: Debian Security Tracker
Related CVEs: CVE-2019-13179
Upstream summary: Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.
Table of contents
Symptom & Impact
calamares-settings-debian ships data files, not a daemon — nothing on Debian 13 listens on a socket because it is installed. The exposure lives in whatever reads those files: a font engine parsing glyph tables, a TLS library consulting the trust store, a runtime resolving a zone name. Symptoms are therefore indirect — a renderer or PDF job crashing on a malformed face, certificate validation accepting or rejecting the wrong issuer, timestamps and scheduled work landing an hour out after a rule change. Long-running processes keep the old copy cached until they are restarted. calamares-settings-debian is a package of static data — fonts, certificates, timezone rules or documentation — read by other programs, so it has no unit of its own to restart; the restarts that matter belong to its consumers.
Environment & Reproduction
Reproduction targets Debian 13. Confirm release with cat /etc/debian_version and lsb_release -a, and the currently installed package with dpkg -l calamares-settings-debian and apt-cache policy calamares-settings-debian. Capture system state with sudo reportbug calamares-settings-debian if you need to file upstream. Trigger the workflow that exposes calamares-settings-debian while collecting journalctl -b, /var/log/apt/history.log, and dpkg -l output.
Root Cause Analysis
Root cause is tracked at Debian Security Tracker. The Debian Security Team shipped fixes in the corresponding calamares-settings-debian point release for Debian 13; running an outdated build leaves the host exposed to the failure modes referenced above. Correlate journalctl --since with apt history (/var/log/apt/history.log) and any kernel taint flags in /proc/sys/kernel/tainted to isolate the originating change.
Quick Triage
Quick triage: sudo apt update && apt list --upgradable, sudo nft list ruleset (or sudo iptables -L), and sudo dpkg --audit. For kernel issues review journalctl -k --since "1 hour ago".
Step-by-Step Diagnosis
1) systemctl --failed. 2) journalctl -xe and . 3) Validate firewall: sudo nft list ruleset or sudo iptables -L -n -v. 4) dpkg -V calamares-settings-debian for integrity. 5) sudo apt install --reinstall calamares-settings-debian if files were tampered. 6) Correlate findings with /var/log/apt/history.log, /var/log/dpkg.log, and Debian Security Tracker to pin the change that introduced the regression.
Solution – Primary Fix
Primary fix: apply the corrective apt transaction documented in Debian Security Tracker. Typical commands: sudo apt update, sudo apt -y install --only-upgrade calamares-settings-debian (or sudo unattended-upgrade -v), then dpkg -l calamares-settings-debian to validate the new build is installed. For kernel advisories add sudo reboot.
Need help rolling this patch across a Debian fleet? Our IT Solutions & Services team manages Debian patch windows with zero-downtime change controls. Get in touch for a free consultation.
Solution – Alternative Approaches
Alternatives include pinning a known-good version via /etc/apt/preferences.d/calamares-settings-debian.pref, holding the package with sudo apt-mark hold calamares-settings-debian, rolling back with sudo apt install calamares-settings-debian=<old-version>, switching firewall backends between iptables-legacy and nftables via update-alternatives --config iptables, or applying the patch from the security archive only — deb debian-13-security main contrib non-free — while delaying the full point-release upgrade.
Verification & Acceptance Criteria
Acceptance: dpkg -l calamares-settings-debian shows the expected fixed version is active shows no errors, apt list --upgradable no longer lists the advisory, sudo nft list ruleset matches the intended policy, and the original reproduction steps for calamares-settings-debian no longer trigger the failure across two consecutive runs.
Rollback Plan
Capture state with apt list --installed > /root/apt-pre.txt and dpkg --get-selections > /root/dpkg-pre.txt. To revert, run sudo apt install --allow-downgrades calamares-settings-debian=<old-version> and reload . Reboot if the kernel or initramfs changed and re-verify symptoms. Where LVM snapshots are in use, sudo lvconvert --merge /dev/<vg>/preupgrade is the fastest rollback path.
Prevention & Hardening
Prevent recurrence by enabling unattended-upgrades with Unattended-Upgrade::Origins-Pattern tuned to origin=Debian,codename=${distro_codename},label=Debian-Security, subscribing to debian-security-announce, mirroring through a local apt-mirror or aptly repo for controlled rollouts, version-locking sensitive packages, and monitoring file integrity with debsums -c or aide --check. Apply CIS Debian hardening and keep needrestart installed so service restarts happen automatically after library upgrades.
Related Errors & Cross-Refs
Related issues that commonly surface alongside calamares-settings-debian: apt lock contention (dpkg --configure -a), systemd unit ordering cycles, firewall rule drift, and kernel taint flags in cat /proc/sys/kernel/tainted. See sibling common-problem articles in this Debian 13 series for adjacent failure modes.
View all debian-13 tutorials on the Tutorials Hub →
Browse all common problems & solutions on the Tutorials Hub.
References & Further Reading
Primary reference: Debian Security Tracker. Supporting docs: Debian Administrators Handbook, man apt, man systemctl, man nft, man iptables, man journalctl, man debsums, the Debian Security Tracker at security-tracker.debian.org, and Debian Security FAQ at debian.org/security/faq. Review /usr/share/doc/calamares-settings-debian/ for component-level notes implicated in calamares-settings-debian.