openSUSE: 2022:0144-1 moderate: cryptsetup
Description
This update for cryptsetup fixes the following issues: - CVE-2021-4122: Fixed possible attacks against data confidentiality through LUKS2 online reencryption extension crash recovery (bsc#1194469).
Patch
Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-144=1
Package List
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): cryptsetup-2.3.7-150300.3.5.1 cryptsetup-debuginfo-2.3.7-150300.3.5.1 cryptsetup-debugsource-2.3.7-150300.3.5.1 libcryptsetup-devel-2.3.7-150300.3.5.1 libcryptsetup12-2.3.7-150300.3.5.1 libcryptsetup12-debuginfo-2.3.7-150300.3.5.1 libcryptsetup12-hmac-2.3.7-150300.3.5.1 - openSUSE Leap 15.3 (noarch): cryptsetup-lang-2.3.7-150300.3.5.1 - openSUSE Leap 15.3 (x86_64): libcryptsetup12-32bit-2.3.7-150300.3.5.1 libcryptsetup12-32bit-debuginfo-2.3.7-150300.3.5.1 libcryptsetup12-hmac-32bit-2.3.7-150300.3.5.1
References
https://www.suse.com/security/cve/CVE-2021-4122.html https://bugzilla.suse.com/1194469