ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
Conclusion & alert: CVE-2015-8946 is rated Low Risk (22.8/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.35%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.13% | 0.35% | +0.22% |
| 2 | 2025-03-30 | 0.21% | 0.13% | -0.08% |
| 3 | 2025-03-29 | — | 0.21% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.3 | 3.0 | LOW |
|
1.8 | 1.4 | [email protected] |
| 2.1 | 2.0 | LOW |
|
3.9 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2015-8946 not yet assigned priority: Debian including 1 source packages (ecryptfs-utils), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2015-8946 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2015-8946 |
suse
|
low | CVE-2015-8946 severity low: SUSE including 4 source package names (ecryptfs-utils, ecryptfs-utils-103-8.3.1, ecryptfs-utils-32bit, ecryptfs-utils-32bit-103-8.3.1), 33 product×package rows across 19 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP2, … (19 product lines)): Fixed 23, Known Not Affected 10. | https://www.suse.com/security/cve/CVE-2015-8946/ |
ubuntu
|
medium | CVE-2015-8946 medium priority: Ubuntu including 1 source packages (ecryptfs-utils), 5 status rows across 5 suites (precise, trusty, upstream, wily, xenial): not-affected 4, released 1. | https://ubuntu.com/security/CVE-2015-8946 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| canonical | ubuntu_linux | 15.10 | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
| ecryptfs | ecryptfs-utils | <= 110 | cpe:2.3:a:ecryptfs:ecryptfs-utils:*:*:*:*:*:*:*:* |