Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-0370

Опубликовано: 02 фев. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-0370: cryptsetup security update (MODERATE)

[2.3.3-4.1]

  • patch: fix CVE-2021-4122.
  • Resolves: #2036906

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

cryptsetup

2.3.3-4.el8_5.1

cryptsetup-devel

2.3.3-4.el8_5.1

cryptsetup-libs

2.3.3-4.el8_5.1

cryptsetup-reencrypt

2.3.3-4.el8_5.1

integritysetup

2.3.3-4.el8_5.1

veritysetup

2.3.3-4.el8_5.1

Oracle Linux x86_64

cryptsetup

2.3.3-4.el8_5.1

cryptsetup-devel

2.3.3-4.el8_5.1

cryptsetup-libs

2.3.3-4.el8_5.1

cryptsetup-reencrypt

2.3.3-4.el8_5.1

integritysetup

2.3.3-4.el8_5.1

veritysetup

2.3.3-4.el8_5.1

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 3 года назад

It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.

CVSS3: 5.9
redhat
больше 3 лет назад

It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.

CVSS3: 4.3
nvd
почти 3 года назад

It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.

CVSS3: 4.3
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 4.3
debian
почти 3 года назад

It was found that a specially crafted LUKS header could trick cryptset ...