Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 538
Alerts This Week
Warning Icon 1 538

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9 articles for you...
100

SUSE 15 SP7 Cryptsetup Moderate Buffer Overflow Security Update 2026-2777-1

An update that solves one vulnerability, contains three features and has three security fixes can now be installed.. # Security update for cryptsetup, s390-tools Announcement ID: SUSE-SU-2026:2777-1 Release Date: 2026-07-06T08:57:17Z Rating: moderate References: * bsc#1241612 * bsc#1259314 * bsc#1261813 * bsc#1270185 * jsc#PED-14586 * jsc#PED-15860 * jsc#PED-15889 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability, contains three features and has three security fixes can now be installed. ## Description: This update for cryptsetup, s390-tools fixes the following issue Security fixes: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185). Changes for s390-tools: * Upgrade s390-tools to version 2.41.0 (jsc#PED-15860) * Automatically set appropriate MTU for HSCI (bsc#1259314) * Changes of existing tools: * chreipl: Make --bootparms work for ECKD re-IPL * cpacfstats: Add 'unauthorized' state to CPU-MF counters * cpictl: Detect RHCOS using VARIANT_ID * hsci: Automatically set appropriate MTU for HSCI * libutil: Add util_readlink() and util_readlinkat() helpers * libutil: Add util_startswith() to util_str * libutil: Add utility parsingfunctions * lschp: Add support for structured output (--format) * lsreipl: Suppress 'clear' output if not supported * pvimg: Add '\--format text' support to 'pvimg info' * pvimg: Add '\--print-schema ' option to 'pvimg info' * pvimg: Add '\--show-secrets' flag to 'pvimg info' * pvimg: Provide improved JSON output to 'pvimg info --format json' * pvinfo: Improve User experience on non-SE enabled systems * zipl/ngdump: Ensure ext4 file system is used on dump partition * zkey: Add support for integrity protected disks using HMAC keys * Bug Fixes: * cpumf/pai: Handle different size of perf_event_attr * lscss: Fix memory leak * zipl: Fix dump job on tape devices \--- s390-tools 2.40 includes --- * Add new tools / libraries: * Add project-wide .clang-tidy configuration * libutil: Introduce util_time for time related functionality * libutil: Introduce zsh/bash autocompletion tooling based on util_opt * pvinfo: Tool to display Secure Execution system information * pvverify: Tool to verify host-key documents * Changes of existing tools: * cpumf: Implement zsh and bash autocompletion * dasdfmt: Implement zsh and bash autocompletion * dbginfo.sh: Add NetworkManager and netplan * dbginfo.sh: Add kvm_stat * dbginfo.sh: Adding stp time information * dbginfo.sh: Simplify procfs collection * hyptop: Add physical information row * hyptop: Calculate sample time delta for physical partition * hyptop: Replace long option names using _ with - for consistency For example: --cpu_types > \--cpu-types (Options with _ are still supported for backward compatibility) * libekmfweb: Add function to validate a certificate against the identity key * netboot: Add longer kernel command lines support * udev/rules.d: Make virtio-blk devices non-rotational * udev/rules.d: Set default io scheduler to 'none' for virtio-blk * ziomon: Add support to sample device symlinks (/dev/disk/...) * ziorep_config: Add fcp-lun details to -M option output * ziorep_config: Add port_idand failed attributes to -A option output * netboot: Install on non-s390 architectures * Bug Fixes: * lib(ekmfweb|kmipclient): Use ln without -r * s390-tools: Fix various compilation issues with musl libc * zipl/boot: Fix unused loadparm when SCLP line-mode console is absent \--- s390-tools 2.39 includes --- * Changes of existing tools: * chpstat: Add options to select IEC units for scaling (SI units are default) * chzdev: Introduce --no-module-load option * cpi: Disable CPI for SEL guests by default * dbginfo.sh: Enhance logging on timeout triggered * iucvterm: Install symlink for lsiucvallow.8 man page * lshwc: Add command line flag to specify individual counters * lspai: Add command line flag for delta values * lspai: Add command line flag for short counter names * lspai: Add command line flag to specify individual counters * lspai: Add command line flags for all cpus * lspai: Add command line flags for hexadecimal output * man: Use CR for constant width font * pvimg: Add '\--image-key' option * zdev: Allow dynamic control of module load * zipl/boot: Fix EBCDIC code page 500 conversion and decrease size by 200 bytes * zipl: Add support of heterogeneous mirrors (remove technical limitations on mirrored targets, thus allowing mirrored devices consist of partitions at different offsets on disks of different types and geometry). * zkey: Add support for generating and importing exportable secure keys * Bug Fixes: * chpstat: Fix scaling of DPU utilization calculation * zdev/dracut: Prevent loading of unused kernel modules * zdev: Fix double device configuration on DPM systems * zdev: Fix double device configuration with rd.dasd * zipl_helper.device-mapper: Fix segfault in an error path \--- s390-tools 2.38 includes --- * Add new tools * udev: New rule to set newly hotplugged CPUs online * zmemtopo: Display memory topology information * zpwr: Display power readings of a partition and CPC * Removed tools / features *check_hostkeydoc: Remove installation target * scsi_logging_level: Delete SCSI logging script (available in sg3_utils) * zdump: Drop build_arch for s390 DASD dumps * zdump: Drop non-extended multi-volume DASD dump support * zdump: Drop support of 32-bit dump architecture * zdump: Drop support of non-extended single volume DASD dumpers * zdump: Drop support of obsolete dumps and dumpers * Changes of existing tools / libraries * Various man-pages fixes * check_hostkeydoc: Add deprecation warning * check_hostkeydoc: Move to scripts directory * cpuplugd: Allow cpu hotplugging on systems without polarization * dbginfo.sh: Add Ubuntu snap tool * dbginfo.sh: Add missing config data and logs * dbginfo.sh: Reworking the container section * dbginfo.sh: Update for network commands * dbginfo.sh: Updating info for disks and lvm * libutil: Add machine type definition for machines 9175 and 9176 * lscpumf: Add support for IBM z17 counter sets * lshwc: Add command line flag for run time * lshwc: Add flags to display counter values in hex * lshwc: Add output '\--format' option * lshwc: Add support for delta counter value display * lspai: Add output '\--format' option * lsreipl: Add secure boot state to output * lswhc: Add short names to lshwc output * pv_tools: Add Bash and Zsh completions * pvapconfig: Add '\--unbind' option * pvimg/boot: Print error messages from stage3a bootloader * pvimg: Add support for CCK update * pvsecret: Add support for CCK update * pvsecret: Allow retrieving secrets by index; warn for duplicated entries * pvsecret: Deny adding secrets with duplicated secret IDs * zdev: Add support for virtio devices * zipl: Enhance mirror support * zipl: Implement '\--dry-run' option for all dump jobs * zipl_helper.device-mapper: Support mirrors over NVMe devices * zkey/dracut: Add a dracut config file for zkey * zkey/initramfs: Update initramfs hook to correct driversand include zkey plugins * zkey: Add support for converting a clear-key LUKS2 volume to use a secure key * Bug Fixes * chpstat: Add missing CMG 5 data fields * chpstat: Fix DPU utilization calculation * libutil/util_file: Handle over-read in util_file_read_fd() * pvattest: Fix successful 'check' evaluation * pvsecret: Fix some edge cases for plaintext keys * zipl_helper.device-mapper: Fix imprecise is_device_mapper() predicate * zkey: Fix EP11 secure key reencipher function * zpcictl: Fix command line parsing for invalid options * Amended the .spec file * "Installing" all shipped rules from etc/udev/rules.d to /usr/lib/udev/rules.d * BuildRequires: cryptsetup-devel > 2.8.2 * Updated the code for IBM z17 machine type 9176: * read_values.c * cputype * Renamed cputype.1 to cputype.8 and amended * Amended read_values.8 * "Improved" the read_values.c: * Added functionalities for '-a' and '-L attributes' * Removed legacy suse_version and sle_version conditionals, standardizing on UsrMerge paths. * Reworked and combined all s390-tools patches (jsc#PED-14586) * Added new combined and reworked patches * Removed obsolete patches * Applied patches (bsc#1261813) * Replace sort_field option with sort * hyptop opts Fix long command line option abbreviations * Removed obsolete patch * Re-vendor-ed vendor.tar.zst Changes for cryptsetup: * Update to 2.8.4: (jsc#PED-15889) * Fix integritysetup resize (grow) of the device if integrity bitmap mode is used. Increasing the integrity device in bitmap mode did not work as integritysetup incorrectly used journal settings that were not applicable. * Fix device size status reports in cryptsetup and integritysetup. If the device uses a sector size larger than 512 bytes, the newly reported byte sizes (introduced in 2.8.0) in the status report were incorrectly displayed. * BITLK: Fix unlocking BitLocker device with recovery passphrase. If the recovery passphrase was present inthe first keyslot, the device failed to unlock. This bug was introduced in 2.8.2 with Clear Key support. * Update to 2.8.3: * Stable bug-fix release with minor extensions. * Update to 2.8.2: * BITLK: Fix for BitLocker metadata validation on big-endian systems. * Update to 2.8.1: * Fix status and deactivation of TCRYPT (VeraCrypt compatible) devices that use chained ciphers. * Fix unlocking BITLK (BitLocker compatible) devices with multibyte UTF8 characters in the passphrase. * Do not allow activation of the LUKS2 device if the used keyslot is not encrypted (it uses a null cipher). * Such a configuration cannot be created by cryptsetup, but can be crafted outside of it. * Null cipher is sometimes used to create an empty container for later reencryption. * Only an empty passphrase can activate such a container (the same as in LUKS1). * Do not silently decrease PBKDF parallel cost (threads) if set by an option. * The maximum parallel cost is limited to 4 threads. * Fixes to configuration and installation scripts. * Meson and autoconf tools now properly support --prefix option for temporary directory installation. * Multiple fixes and cleanups to config.h for compatibility between Meson and autoconf. * Fix the luks2-external-tokens-path Meson option to work the same as in autoconf. * Fix Meson install for tool binaries, install fvault2Open man page and include test/fuzz/meson.build in release. * Major update to manual pages. * Try to explain the PBKDF hardcoded limits. * Add a better explanation for automatic integrity tag recalculation. * Mention crypt/verity/integritytab. * Remove or reformulate some misleading warnings present only with old and no longer supported kernels. * Clarify that some commands do not wipe data and unify OPAL reset wording. * Clarify the --label option. * There are also many other grammar and stylistic fixes to unify the man-page style. * Fixes for false-positive and annoying (optional)warnings added in recent compilers. * Update to 2.8.0: * Full release notes in: * https://cdn.kernel.org/pub/linux/utils/cryptsetup/v2.8/v2.8.0-ReleaseNotes * Introduce support for inline mode (use HW sectors with additional hardware metadata space). * Finalize use of keyslot context API. * Make all keyslot context types fully self-contained. * Add --key-description and --new-key-description cryptsetup options. * Support more precise keyslot selection in reencryption initialization. * Allow reencryption to resume using token and volume keys. * Cryptsetup repair command now tries to check LUKS keyslot areas for corruption. * Opal2 SED: PSID keyfile is now expected to be 32 alphanumeric characters. * Opal2: Avoid the Erase method and use Secure Erase for locking range. * Opal2: Fix some error description (in debug only). * Opal2: Do not allow deferred deactivation. * Allow --reduce-device-size and --device-size combination for reencryption (encrypt) action. * Fix the userspace storage backend to support kernel "capi:" cipher specification format. * Disallow conversion from LUKS2 to LUKS1 if kernel "capi:" cipher specification is used. * Explicitly disallow kernel "capi:" cipher specification format for LUKS2 keyslot encryption. * Do not allow conversion of LUKS2 to LUKS1 if an unbound keyslot is present. * cryptsetup: Adjust the XTS key size for kernel "capi:" cipher specification. * Remove keyslot warning about possible failure due to low memory. * Do not limit Argon2 KDF memory cost on systems with more than 4GB of available memory. * Properly report out of memory error for cryptographic backends implementing Argon2. * Avoid KDF2 memory cost overflow on 32-bit platforms. * Do not use page size as a fallback for device block size. * veritysetup: Check hash device size in advance. * Print a better error message for unsupported LUKS2 AEAD device resize. * Optimize LUKS2 metadata writes. * veritysetup: support--error-as-corruption option. * Report all sizes in status and dump command output in the correct units. * Add --integrity-key-size option to cryptsetup. * Support trusted; encrypted keyrings for plain devices. * Support plain format resize with a keyring key. * TCRYPT: Clear mapping of system-encrypted partitions. * TCRYPT: Print all information from the decrypted metadata header in the tcryptDump command. * Always lock the volume key structure in memory. * Do not run direct-io read check on block devices. * Fix a possible segfault in deferred deactivation. * Exclude cipher allocation time from the cryptsetup benchmark. * Add Mbed-TLS optional crypto backend. * Fix the wrong preprocessor use of #ifdef for config.h processed by Meson. * Reorganize license files. The license text files are now in docs/licenses. The COPYING file in the root directory is the default license. * Remove cc-by-sa-4.0.txt as already shipped now in docs/licenses and named as COPYING.CC-BY-SA-4.0. * Libcryptsetup API extensions. The libcryptsetup API is backward compatible with all existing symbols. Due to the self-contained memory allocation, these symbols have the new version: * crypt_keyslot_context_init_by_passphrase; * crypt_keyslot_context_init_by_keyfile; * crypt_keyslot_context_init_by_token; * crypt_keyslot_context_init_by_volume_key; * crypt_keyslot_context_init_by_signed_key; * crypt_keyslot_context_init_by_keyring; * crypt_keyslot_context_init_by_vk_in_keyring; * New symbols: * crypt_format_inline * crypt_get_old_volume_key_size * crypt_reencrypt_init_by_keyslot_context * crypt_safe_memcpy * New defines: * CRYPT_ACTIVATE_HIGH_PRIORITY * CRYPT_ACTIVATE_ERROR_AS_CORRUPTION * CRYPT_ACTIVATE_INLINE_MODE * CRYPT_REENCRYPT_CREATE_NEW_DIGEST * New requirement flag: * CRYPT_REQUIREMENT_INLINE_HW_TAGS * Add a dependency on device-mapper to libcryptsetup12 to install the required device-mapper udev rules.(bsc#1241612) * Update to 2.7.5: * Fix possible online reencryption data corruption (only in 2.7.x). In some situations (initializing a suspended device-mapper device), cryptsetup disabled direct-io device access. This caused unsafe online reencryption operations that could lead to data corruption. The code now adds strict checks (and aborts the operation) and changes direct-io detection code to prevent data corruption. * Fix a clang compilation error in SSH token plugin. As clang linker treats missing symbols as errors, the linker phase for the SSH token failed as the optional cryptsetup_token_buffer_free was not defined. * Fix crypto backend initialization in crypt_format_luks2_opal API call. * Update to 2.7.4: * Detect device busy failure for device-mapper table-referenced devices. * Fix shared activation for dm-verity devices. * Add --shared option for veritysetup open action. * Do not use exclusive flag for the allocated backing loop files. * Fixes for problems found by static analyzers and Valgrind. * Fixes to tests and CI scripts. * Use fdupes to link identical man pages. * Update to 2.7.3: * Do not allow formatting LUKS2 with Opal SED (hardware encryption) if the reported logical sector size for the block device and Opal encryption logical block differs. * Fixes to wiping LUKS2 headers after Opal locking area erase. * Mention the need for possible PSID revert before Opal format for some drives (man page). * Fix Bitlocker-compatible code to ignore newly seen metadata entries. * Fix interactive query retry if LUKS2 unbound keyslot is present. * Detect unsupported zoned devices for LUKS header devices. * Allow "capi" cipher format for benchmark command and fix parsing of plain IV in "capi" format. * Add support for HCTR2 encryption mode. * Source code now uses SPDX license identifiers instead of full license preambles. * Fix missing includes for cryptographic backend that could cause compilation errorsfor some systems. * Fix tests to work correctly in FIPS mode with recent OpenSSL 3.2. * Fix various (mostly false positive) issues detected by Coverity. * License: Replace legacy 'AND SUSE-GPL-2.0-with-openssl-exception' with 'WITH cryptsetup-OpenSSL-exception' (the official SPDX exception). * update to 2.7.2: * Fix activation of OPAL-only encrypted LUKS device with tokens * Fix formatting of OPAL devices with 4096-byte sector size * Fix incorrect OPAL locking range alignment calculation if used over an unaligned device partition. * Do not check the passphrase quality for OPAL Admin PIN, as this passphrase already exists. * Update license for FAQ document to CC BY-SA 4.0. NOTE: Please note that with OPAL-only (--hw-opal-only) encryption, the configured OPAL administrator PIN (passphrase) allows unlocking all configured locking ranges without LUKS keyslot decryption (without knowledge of LUKS passphrase). Because of many observed problems with compatibility, cryptsetup currently DOES NOT use OPAL single-user mode, which would allow such decoupling of OPAL admin PIN access. * Update to 2.7.1: * Fix interrupted LUKS1 decryption resume. With the replacement of the cryptsetup-reencrypt tool by the cryptsetup reencrypt command, resuming the interrupted LUKS1 decryption operation could fail. LUKS2 was not affected. * Allow --link-vk-to-keyring with --test-passphrase option. This option allows uploading the volume key in a user-specified kernel keyring without activating the device. * Fix crash when --active-name was used in decryption initialization. * Updates and changes to man pages, including indentation, sorting options alphabetically, fixing mistakes in crypt_set_keyring_to_link, and fixing some typos. * Fix compilation with libargon2 when --disable-internal-argon2 was used. * Do not require installed argon2.h header and never compile internal libargon2 code if the crypto library directly supports Argon2. * Fixesto regression tests to support older Linux distributions. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2777=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cryptsetup-2.8.4-150700.6.4.4 * cryptsetup-debuginfo-2.8.4-150700.6.4.4 * libcryptsetup-devel-2.8.4-150700.6.4.4 * cryptsetup-ssh-2.8.4-150700.6.4.4 * libcryptsetup12-2.8.4-150700.6.4.4 * cryptsetup-debugsource-2.8.4-150700.6.4.4 * libcryptsetup12-debuginfo-2.8.4-150700.6.4.4 * cryptsetup-ssh-debuginfo-2.8.4-150700.6.4.4 * Basesystem Module 15-SP7 (s390x x86_64) * s390-tools-2.41.0-150700.4.26.2 * Basesystem Module 15-SP7 (noarch) * s390-tools-genprotimg-data-2.41.0-150700.4.26.2 * cryptsetup-doc-2.8.4-150700.6.4.4 * cryptsetup-lang-2.8.4-150700.6.4.4 * Basesystem Module 15-SP7 (s390x) * s390-tools-debuginfo-2.41.0-150700.4.26.2 * s390-tools-debugsource-2.41.0-150700.4.26.2 * libekmfweb1-2.41.0-150700.4.26.2 * s390-tools-zdsfs-debuginfo-2.41.0-150700.4.26.2 * libkmipclient1-2.41.0-150700.4.26.2 * osasnmpd-2.41.0-150700.4.26.2 * libkmipclient1-debuginfo-2.41.0-150700.4.26.2 * libekmfweb1-devel-2.41.0-150700.4.26.2 * s390-tools-chreipl-fcp-mpath-2.41.0-150700.4.26.2 * s390-tools-hmcdrvfs-debuginfo-2.41.0-150700.4.26.2 * s390-tools-hmcdrvfs-2.41.0-150700.4.26.2 * osasnmpd-debuginfo-2.41.0-150700.4.26.2 * libekmfweb1-debuginfo-2.41.0-150700.4.26.2 * s390-tools-zdsfs-2.41.0-150700.4.26.2 * Basesystem Module 15-SP7 (x86_64) * libcryptsetup12-32bit-debuginfo-2.8.4-150700.6.4.4 * libcryptsetup12-32bit-2.8.4-150700.6.4.4 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1241612 *https://bugzilla.suse.com/show_bug.cgi?id=1259314 * https://bugzilla.suse.com/show_bug.cgi?id=1261813 * https://bugzilla.suse.com/show_bug.cgi?id=1270185 * https://jira.suse.com/browse/PED-14586 * https://jira.suse.com/browse/PED-15860 * https://jira.suse.com/browse/PED-15889 . An update for SUSE resolves a critical security issue in cryptsetup and s390-tools, ensuring improved system protection.. SUSE update, cryptsetup security, system patch, s390-tools fix, Moderate risk advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 06, 2026 moderate SuSE
100

SUSE: 2023:2543-1 Moderate: pcre2 Denial Of Service Fix

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.2/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2543-1 Container Tags : suse/sle-micro/5.2/toolbox:12.1 , suse/sle-micro/5.2/toolbox:12.1-6.2.254 , suse/sle-micro/5.2/toolbox:latest Container Release : 6.2.254 Severity : moderate Type : security References : 1211079 1213514 CVE-2022-41409 ----------------------------------------------------------------- The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3210-1 Released: Mon Aug 7 15:20:04 2023 Summary: Security update for pcre2 Type: security Severity: moderate References: 1213514,CVE-2022-41409 This update for pcre2 fixes the following issues: - CVE-2022-41409: Fixed integer overflow vulnerability in pcre2test that allows attackers to cause a denial of service via negative input (bsc#1213514). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3218-1 Released: Mon Aug 7 16:52:13 2023 Summary: Recommended update for cryptsetup Type: recommended Severity: moderate References: 1211079 This update for cryptsetup fixes the following issues: - Handle system with low memory and no swap space (bsc#1211079) The following package changes have been done: - libcryptsetup12-hmac-2.3.7-150300.3.8.1 updated - libcryptsetup12-2.3.7-150300.3.8.1 updated - libpcre2-8-0-10.31-150000.3.15.1 updated . SUSE Container Upgrade Notice: suse/sle-micro/5.2/toolbox Container Notice ID: SUSE-CU-2023:2544. SUSE Update, Toolbox Container, Security Fixes, Container Patches. . LinuxSecurity.com Team

Calendar%202 Aug 09, 2023 SuSE
219

Rocky Linux 8 RLSA-2022:370 Moderate: Cryptsetup Update Threat

Moderate: cryptsetup security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2022:370', 'synopsis': 'Moderate: cryptsetup security update', 'severity': 'Moderate', 'topic': 'An update for cryptsetup is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The cryptsetup packages provide a utility for setting up disk encryption using the dm-crypt kernel module.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2032401'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-4122.json:::CVE-2021-4122'], 'references': [], 'publishedAt': '2022-02-02T04:36:32.015968Z', 'rpms': ['cryptsetup-2.3.3-4.el8_5.1.aarch64.rpm', 'cryptsetup-2.3.3-4.el8_5.1.src.rpm', 'cryptsetup-2.3.3-4.el8_5.1.x86_64.rpm', 'cryptsetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm', 'cryptsetup-debuginfo-2.3.3-4.el8_5.1.i686.rpm', 'cryptsetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm', 'cryptsetup-debugsource-2.3.3-4.el8_5.1.aarch64.rpm', 'cryptsetup-debugsource-2.3.3-4.el8_5.1.i686.rpm', 'cryptsetup-debugsource-2.3.3-4.el8_5.1.x86_64.rpm', 'cryptsetup-devel-2.3.3-4.el8_5.1.aarch64.rpm', 'cryptsetup-devel-2.3.3-4.el8_5.1.i686.rpm', 'cryptsetup-devel-2.3.3-4.el8_5.1.x86_64.rpm', 'cryptsetup-libs-2.3.3-4.el8_5.1.aarch64.rpm', 'cryptsetup-libs-2.3.3-4.el8_5.1.i686.rpm', 'cryptsetup-libs-2.3.3-4.el8_5.1.x86_64.rpm', 'cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm', 'cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.i686.rpm', 'cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm', 'cryptsetup-reencrypt-2.3.3-4.el8_5.1.aarch64.rpm','cryptsetup-reencrypt-2.3.3-4.el8_5.1.x86_64.rpm', 'cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm', 'cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm', 'integritysetup-2.3.3-4.el8_5.1.aarch64.rpm', 'integritysetup-2.3.3-4.el8_5.1.x86_64.rpm', 'integritysetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm', 'integritysetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm', 'veritysetup-2.3.3-4.el8_5.1.aarch64.rpm', 'veritysetup-2.3.3-4.el8_5.1.x86_64.rpm', 'veritysetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm', 'veritysetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm']}\. Rocky Linux 8 has released a significant security patch for OpenSSL, targeting possible risks and weaknesses.. Rocky Linux Security, Cryptsetup Update, Disk Encryption, Security Patch. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2022 Rocky Linux
172

Ubuntu 20.04 LTS: USN-5286-1 Moderate: Cryptsetup Sensitive Exposure

cryptsetup could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-5286-1 February 15, 2022 cryptsetup vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS Summary: cryptsetup could be made to expose sensitive information. Software Description: - cryptsetup: disk encryption support Details: Milan Broz discovered that cryptsetup incorrectly handled LUKS2 reencryption recovery. An attacker with physical access to modify the encrypted device header may trigger the device to be unencrypted the next time it is mounted by the user. On Ubuntu 20.04 LTS, this issue was fixed by disabling the online reencryption feature. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: cryptsetup 2:2.3.7-0ubuntu0.21.10.1 Ubuntu 20.04 LTS: cryptsetup 2:2.2.2-3ubuntu2.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5286-1 CVE-2021-4122 Package Information: https://launchpad.net/ubuntu/+source/cryptsetup/2:2.3.7-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/cryptsetup/2:2.2.2-3ubuntu2.4 . A flaw in Cryptsetup exposes confidential data on Ubuntu machines, signaling a major security threat.. Cryptsetup Vulnerability, Ubuntu Security Notice, Sensitive Information Exposure. . LinuxSecurity.com Team

Calendar%202 Feb 15, 2022 Ubuntu
87

Debian Bullseye DSA-5070-1 Critical: Cryptsetup Decryption Problem

CVE-2021-4122 Milan Broz, its maintainer, discovered an issue in cryptsetup, the disk encryption configuration tool for Linux. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5070-1 security@debian.org https://www.debian.org/security/ Yves-Alexis Perez February 10, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : cryptsetup CVE ID : CVE-2021-4122 Debian Bug : 1003686 949336 CVE-2021-4122 Milan Broz, its maintainer, discovered an issue in cryptsetup, the disk encryption configuration tool for Linux. LUKS2 (an on-disk format) online reencryption is an optional extension to allow a user to change the data reencryption key while the data device is available for use during the whole reencryption process. An attacker can modify on-disk metadata to simulate decryption in progress with crashed (unfinished) reencryption step and persistently decrypt part of the LUKS2 device (LUKS1 devices are indirectly affected as well, see below). This attack requires repeated physical access to the LUKS2 device but no knowledge of user passphrases. The decryption step is performed after a valid user activates the device with a correct passphrase and modified metadata. The size of possible decrypted data per attack step depends on configured LUKS2 header size (metadata size is configurable for LUKS2). With the default LUKS2 parameters (16 MiB header) and only one allocated keyslot (512 bit key for AES-XTS), simulated decryption with checksum resilience SHA1 (20 bytes checksum for 4096-byte blocks), the maximal decrypted size can be over 3GiB. The attack is not applicable to LUKS1 format, but the attacker can update metadata in place to LUKS2 format as an additional step. For such a converted LUKS2header, the keyslot area is limited to decrypted size (with SHA1 checksums) over 300 MiB. LUKS devices that were formatted using a cryptsetup binary from Debian Stretch or earlier are using LUKS1. However since Debian Buster the default on-disk LUKS format version is LUKS2. In particular, encrypted devices formatted by the Debian Buster and Bullseye installers are using LUKS2 by default. Key truncation in dm-integrity This update additionaly fixes a key truncation issue for standalone dm-integrity devices using HMAC integrity protection. For existing such devices with extra long HMAC keys (typically > 106 bytes of length), one might need to manually truncate the key using integritysetup(8)'s `--integrity-key-size` option in order to properly map the device under 2:2.3.7-1+deb11u1 and later. Only standalone dm-integrity devices are affected. dm-crypt devices, including those using authenticated disk encryption, are unaffected. For the oldstable distribution (buster), this problem is not present. For the stable distribution (bullseye), this problem has been fixed in in version 2:2.3.7-1+deb11u1. We recommend that you upgrade your cryptsetup packages. For the detailed security status of cryptsetup please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cryptsetup Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Announcement DSA-5071-2 reveals a serious vulnerability in the GnuPG tool, necessitating prompt updates for impacted users.. Debian Security Advisory,Cryptsetup Update,Linux Disk Encryption. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 10, 2022 Critical Debian
203

Mageia 8 MGASA-2022-0047 Critical: Cryptsetup Decryption Issue

An attacker can modify on-disk metadata to simulate decryption in progress with crashed (unfinished) reencryption step and persistently decrypt part of the LUKS device (CVE-2021-4122). References: . MGASA-2022-0047 - Updated cryptsetup packages fix security vulnerability Publication date: 03 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0047.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-4122 An attacker can modify on-disk metadata to simulate decryption in progress with crashed (unfinished) reencryption step and persistently decrypt part of the LUKS device (CVE-2021-4122). References: - https://bugs.mageia.org/show_bug.cgi?id=29884 - https://www.openwall.com/lists/oss-security/2022/01/13/2 - https://www.cve.org/CVERecord?id=CVE-2021-4122 SRPMS: - 8/core/cryptsetup-2.3.7-1.mga8 . MGASA-2022-0048 tackles a vulnerability in the systemd package that could enable malicious users to exploit services and escalate privileges.. Mageia Cryptsetup Update, Security Advisory Mageia, Cryptsetup Vulnerability, LUKS Device Risk, Mageia Security Alert. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 03, 2022 Critical Mageia
217

Oracle Linux 8 ELSA-2022-0370 Moderate: Cryptsetup Security Advisory

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-0370 https://linux.oracle.com/errata/ELSA-2022-0370.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: cryptsetup-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-devel-2.3.3-4.el8_5.1.i686.rpm cryptsetup-devel-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-libs-2.3.3-4.el8_5.1.i686.rpm cryptsetup-libs-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-reencrypt-2.3.3-4.el8_5.1.x86_64.rpm integritysetup-2.3.3-4.el8_5.1.x86_64.rpm veritysetup-2.3.3-4.el8_5.1.x86_64.rpm aarch64: cryptsetup-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-devel-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-libs-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-reencrypt-2.3.3-4.el8_5.1.aarch64.rpm integritysetup-2.3.3-4.el8_5.1.aarch64.rpm veritysetup-2.3.3-4.el8_5.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/cryptsetup-2.3.3-4.el8_5.1.src.rpm Related CVEs: CVE-2021-4122 Description of changes: [2.3.3-4.1] - patch: fix CVE-2021-4122. - Resolves: #2036906 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 has been issued with a significant update ELSA-2022-0370 for cryptsetup, mitigating CVE-2021-4122 security vulnerabilities.. Oracle Linux Update, Cryptsetup Security, ELSA-2022-0370. . LinuxSecurity.com Team

Calendar%202 Feb 02, 2022 Oracle
98

RHEL 8 RHSA-2022:0370-03 Moderate: Cryptsetup Encryption Threat

An update for cryptsetup is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: cryptsetup security update Advisory ID: RHSA-2022:0370-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:0370 Issue date: 2022-02-01 CVE Names: CVE-2021-4122 ==================================================================== 1. Summary: An update for cryptsetup is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The cryptsetup packages provide a utility for setting up disk encryption using the dm-crypt kernel module. Security Fix(es): * cryptsetup: disable encryption via header rewrite (CVE-2021-4122) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2032401 - CVE-2021-4122 cryptsetup: disable encryption via header rewrite 6. PackageList: Red Hat Enterprise Linux AppStream (v. 8): aarch64: cryptsetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-devel-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm ppc64le: cryptsetup-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-devel-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm s390x: cryptsetup-debuginfo-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-devel-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.s390x.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.s390x.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.s390x.rpm x86_64: cryptsetup-debuginfo-2.3.3-4.el8_5.1.i686.rpm cryptsetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.i686.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-devel-2.3.3-4.el8_5.1.i686.rpm cryptsetup-devel-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.i686.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.i686.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.i686.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.i686.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm Red Hat Enterprise Linux BaseOS (v.8): Source: cryptsetup-2.3.3-4.el8_5.1.src.rpm aarch64: cryptsetup-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-libs-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-reencrypt-2.3.3-4.el8_5.1.aarch64.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm integritysetup-2.3.3-4.el8_5.1.aarch64.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm veritysetup-2.3.3-4.el8_5.1.aarch64.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.aarch64.rpm ppc64le: cryptsetup-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-libs-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-reencrypt-2.3.3-4.el8_5.1.ppc64le.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm integritysetup-2.3.3-4.el8_5.1.ppc64le.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm veritysetup-2.3.3-4.el8_5.1.ppc64le.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.ppc64le.rpm s390x: cryptsetup-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-debuginfo-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-libs-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-reencrypt-2.3.3-4.el8_5.1.s390x.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.s390x.rpm integritysetup-2.3.3-4.el8_5.1.s390x.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.s390x.rpm veritysetup-2.3.3-4.el8_5.1.s390x.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.s390x.rpm x86_64: cryptsetup-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-debuginfo-2.3.3-4.el8_5.1.i686.rpm cryptsetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.i686.rpm cryptsetup-debugsource-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-libs-2.3.3-4.el8_5.1.i686.rpm cryptsetup-libs-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.i686.rpm cryptsetup-libs-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-reencrypt-2.3.3-4.el8_5.1.x86_64.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.i686.rpm cryptsetup-reencrypt-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm integritysetup-2.3.3-4.el8_5.1.x86_64.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.i686.rpm integritysetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm veritysetup-2.3.3-4.el8_5.1.x86_64.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.i686.rpm veritysetup-debuginfo-2.3.3-4.el8_5.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-4122 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYfm//NzjgjWX9erEAQjZ8hAApB5myZcrYlQ1+gLF/xxVDVfAlHnfwmy/ WvaOHaSE7a4yvNopoFyUDn8DLV7zn04u5f0AxoAI3UyJaUTDhz8mfwQkR3j1dkRV mpSubgTcQFVswrSpxWUfzl1rV8eMUc97yf5Ty+fnSt/vqkho75gupwglUBdxlJYh 3bKH2+pjY9l73rULDRyTT8l/Jri18mb1cw2EZAVCs7pWsYgXYmbnHh5jhDC9YrLr XbfAJQ2qFsyu54J5Q9BeRWXBrW9xwtjKC3SJ4iM0rklPm6MZACkbARehmpUTVJkS UK8ur1wnj29VIGu/b5kcsF7hXLcfUU2ab2W+wx9tPLkahs3ULsa7sG7GRfs8hwQk 5qkS9V3LSwipuOIalffwWVERrVAjv00zam/+LiPynlbwyJOYmOWIrf6c/wsIqKcN i+AvDAo0F0wg2TuggIM0qrQOPCedrlOxdCejlZQgFd54OQ2GQ8BxizYkZmdSYIf0 QF4ZLzHwQZZzjINI0ee2o7p7iXT3JSv4nvLH10pKO3F5fs/ORPKnxsyixi4sJ79G 5nqjDuR5YEfvUDdugQNhEwF7EXobqSNvvZjY1Sd57moDTGB2W3h/tQ42joIlG+Bo FXl4P8DnXFnd24TcUav1glvLFg7sjhvkZ6uvNJqBL2ufXTB+IdshxpcE1wxW6+9V XdNC7pxzTTU=vCFF -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . An important patch for cryptsetup in RHEL 8 addresses potential vulnerabilities in encryption mechanisms with robust remediation strategies.. Red Hat Security, cryptsetup Update, enterprise Linux, encryption utility, security advisory. .LinuxSecurity.com Team

Calendar%202 Feb 01, 2022 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200