First published 23 May 2023

CVSS 3.1: 2.3 (Low)

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Summary

A bug in the IGEL OS Setup application prevents users from setting a (new) password for Device Encryption, and from disabling Device Encryption. This affects the following IGEL products:

  • IGEL OS 11.08.290

Details

Due to a bug in the IGEL OS Setup application, users of IGEL OS 11.08.290

  • cannot set a (new) password for Device Encryption
  • cannot deactivate Device Encryption

The severity of this issue is low. Device Encryption settings and passwords that have been set before upgrading to IGEL OS 11.08.290 are not affected by this bug. They remain the same.

Mitigation

If you cannot update to IGEL OS 11.08.330 yet, you can apply the following mitigation:

  1. Go to Setup > System > Firmware Customization> Custom Commands.

  2. Enter the following command in the Desktop initialization field:
    systemctl start igel-kml-daemon

  3. Reboot the system.

Update Instructions

  • Update to IGEL OS version 11.08.330 (and set a Device Encryption password after the upgrade, if desired).