Wind River Support Network

HomeDefectsLIN1021-2436
Fixed

LIN1021-2436 : Security Advisory - cryptsetup - CVE-2021-4122

Created: Jan 13, 2022    Updated: Aug 25, 2022
Resolved Date: Apr 26, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.12
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.

https://nvd.nist.gov/vuln/detail/CVE-2021-4122

CVEs


Live chat
Online