Cryptsetup vulnerability - when will it be taken care of?

2016-11-21

deshmukh gravatar image

This link talks about a serious vulnerability of cryptsetup.

My disk is encrypted and the system is updated. I could enter the shell as described in the above link by hitting Enter for for than a minute.

When shoud we expect Fedora to take care of this vulnerability?

As far as i understand this bug, it "only" results in a terminal with root permissions. Your data is still encrypted! And if some bad guy is able to gain physical access to your device you're f*cked up anyway - with physical access everybody can be root, with or without this vulnerability.

jake ( 2016-11-22 )

@jake I could not understand the article referred to in the link fully but what I gather is there is a possibility of remote access AFTER the initial physical access. That is scary, IMHO.

deshmukh ( 2016-11-24 )

That's a point i didn't even think of, your absolutely right, that is scary!

jake ( 2016-11-25 )

1 Answer

2016-11-21

sideburns gravatar image

A little research shows me that cryptsetup is a front-end for dm-crypt, which is neither written nor maintained by the Fedora Project. Thus, Fedora can't directly deal with this issue. All you can do is wait until the project's maintainers release a patch, after which it will be provided as an update as soon as it's been tested.

