Insufficient verification of data authenticity in cryptsetup - CVE-2021-4122

 

Insufficient verification of data authenticity in cryptsetup - CVE-2021-4122

Published: May 27, 2022


Vulnerability identifier: #VU63770
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-4122
CWE-ID: CWE-345
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to escalate privileges on the system.

The vulnerability exists due to improper handling of the LUKS2 reencryption recover. A local attacker with physical access to the medium can send a specially crafted LUKS header and trick cryptsetup into disabling encryption during the recovery of the device.

Affected software

cryptsetup
Amazon Linux AMI
SUSE MicroOS
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
SUSE Linux Enterprise Module for Basesystem
openEuler
Ubuntu
Fedora
Netcool Operations Insight
IBM Robotic Process Automation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenStack
Cloud Pak for Security (CP4S)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
cryptsetup (Ubuntu package)
integritysetup
cryptsetup-reencrypt
cryptsetup-libs
cryptsetup-devel
cryptsetup
veritysetup
cryptsetup (Red Hat package)
cryptsetup-help
cryptsetup-debuginfo
cryptsetup-debugsource
libcryptsetup12-32bit
cryptsetup-lang
libcryptsetup-devel
libcryptsetup12-hmac
libcryptsetup12-32bit-debuginfo
libcryptsetup12-debuginfo
libcryptsetup12
libcryptsetup12-hmac-32bit

How to mitigate CVE-2021-4122

Install updates from vendor's website.

cryptsetup - addressed in versions 2.3.7, 2.4.3
Netcool Operations Insight - update to 1.6.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Robotic Process Automation - update to 21.0.2.2
OpenShift API for Data Protection (OADP) - update to 1.0.1
Migration Toolkit for Containers - update to 1.5.4
cryptsetup (Ubuntu package) - addressed in versions 2:2.2.2-3ubuntu2.4, 2:2.3.7-0ubuntu0.21.10.1
integritysetup - update to 2.3.3-4
cryptsetup-reencrypt - update to 2.3.3-4
cryptsetup-libs - update to 2.3.3-4
cryptsetup-devel - update to 2.3.3-4
cryptsetup - update to 2.3.3-4
veritysetup - update to 2.3.3-4
cryptsetup (Red Hat package) - update to 2.3.3-4.el8_5.1
cryptsetup-help - update to 2.3.3-6
cryptsetup-debuginfo - update to 2.3.3-6
cryptsetup-devel - update to 2.3.3-6
veritysetup - update to 2.3.3-6
cryptsetup-reencrypt - update to 2.3.3-6
cryptsetup-debugsource - update to 2.3.3-6
cryptsetup - update to 2.3.3-6
integritysetup - update to 2.3.3-6
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.6
cryptsetup - addressed in versions 2.3.7-1.fc34, 2.4.3-1.fc35
libcryptsetup12-32bit - update to 2.3.7-150300.3.5.1
cryptsetup-lang - update to 2.3.7-150300.3.5.1
libcryptsetup-devel - update to 2.3.7-150300.3.5.1
libcryptsetup12-hmac - update to 2.3.7-150300.3.5.1
libcryptsetup12-32bit-debuginfo - update to 2.3.7-150300.3.5.1
libcryptsetup12-debuginfo - update to 2.3.7-150300.3.5.1
libcryptsetup12 - update to 2.3.7-150300.3.5.1
cryptsetup-debugsource - update to 2.3.7-150300.3.5.1
cryptsetup-debuginfo - update to 2.3.7-150300.3.5.1
cryptsetup - update to 2.3.7-150300.3.5.1
libcryptsetup12-hmac-32bit - update to 2.3.7-150300.3.5.1
cryptsetup - update to 2.4.3-2
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins