OESA-2022-1532
Dashboard / Vulnerabilities / OESA-2022-1532
Summary: cryptsetup security update
Details: cryptsetup is a utility used to conveniently set up disk encryption based on the DMCrypt kernel module. Security Fix(es): It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.(CVE-2021-4122)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1532, https://nvd.nist.gov/vuln/detail/CVE-2021-4122
Affected packages
Package
Name: cryptsetup
Purl: pkg:rpm/openEuler/cryptsetup&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
