QID 198664

Date Published: 2022-02-16

QID 198664: Ubuntu Security Notification for cryptsetup Vulnerability (USN-5286-1)

Cryptsetup incorrectly handled luks2reencryption recovery.

An attacker with physical access to modify theencrypted device header may trigger the device to be unencrypted the nexttime it is mounted by the user.
04 lts, this issue was fixed by disabling the onlinereencryption feature.

  • CVSS V3 rated as High - 6.2 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5286-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198664

    Software Advisories
    Advisory ID Software Component Link
    USN-5286-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5286-1