Page 1 of 1

To Devs: please update cryptsetup package soon

Posted: Tue Jan 18, 2022 3:48 am
by grelos
Following this report, please update in the repository to cryptsetup 2.4.3 Thanks

https://nakedsecurity.sophos.com/2022/0 ... patch-now/

Re: To Devs: please update cryptsetup package soon

Posted: Tue Jan 18, 2022 4:08 am
by Eadwine Rose
Moved to package requests.

Re: To Devs: please update cryptsetup package soon

Posted: Tue Jan 18, 2022 10:05 am
by SwampRabbit
Please see https://security-tracker.debian.org/tra ... -2021-4122

The version in MX-19 (Debian Buster is not affected).

Also please bear in mind that exploiting this requires repeated physical access to the vulnerable LUKS device.

Re: To Devs: please update cryptsetup package soon

Posted: Tue Jan 18, 2022 2:02 pm
by Stevo
My guess is that with it requiring repeated physical access, it's really not high priority, so a patch will be coming with the next Debian point release.

Re: To Devs: please update cryptsetup package soon

Posted: Sat Feb 12, 2022 2:27 pm
by Lvl2u
so, what if I download the newest version of cryptseptup and install the TAR manually?

Yeah, Im a begginer

Re: To Devs: please update cryptsetup package soon

Posted: Sat Feb 12, 2022 2:48 pm
by dolphin_oracle

Re: To Devs: please update cryptsetup package soon

Posted: Sat Feb 12, 2022 2:56 pm
by SwampRabbit
Lvl2u wrote: Sat Feb 12, 2022 2:27 pm ...
Yeah, Im a begginer
You're also a Porygon it seems...

Sorry I couldn't help it :p

Re: To Devs: please update cryptsetup package soon

Posted: Sat Feb 12, 2022 3:25 pm
by Lvl2u
SwampRabbit wrote: Sat Feb 12, 2022 2:56 pm
Lvl2u wrote: Sat Feb 12, 2022 2:27 pm ...
Yeah, Im a begginer
You're also a Porygon it seems...

Sorry I couldn't help it :p
It's ok, I will UPGRADE anyways ;)