Slackware64-current ChangeLog (2022-01-14)

Fri Jan 14 05:24:07 UTC 2022

  • a/cryptsetup-2.4.3-x86_64-1.txz
    This update addresses a multi-step attack on LUKS2 format by orchestrating
    LUKS2 reencryption metadata in existing LUKS2 header. An attacker is able to
    trigger permanent data decryption (ciphertext→plaintext transformation) on
    part of data device on next LUKS2 device activation. Attacker does _not_
    have to know passphrase or decrypted volume encryption key.
    cryptsetup versions older than 2.2.0 are not affected by this, because they
    do not support online LUKS2 reencryption.
    For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4122
    (* Security fix *)
  • news/2022/01/14/slackware64-current-changelog.txt
  • Last modified: 9 days ago
  • by Giuseppe Di Terlizzi