DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [dm-crypt] About CVE-2016-4484: - Cryptsetup Initrd root Shell
@ 2016-11-15 12:34 Milan Broz
  2016-11-15 13:27 ` Arno Wagner
                   ` (2 more replies)
  0 siblings, 3 replies; 18+ messages in thread
From: Milan Broz @ 2016-11-15 12:34 UTC (permalink / raw)
  To: dm-crypt

Hi all,

just little bit clarification about CVE-2016-4484
http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html

This bug is *NOT* cryptsetup/LUKS upstream bug, it is a minor problem in scripts
unlocking an encrypted system.

It allows attacker to drop to initramdisk shell (without decryption of LUKS data).

The scripts are part of Debian cryptsetup package (as an addition to upstream)
or part of dracut package (if dracut is used).

(The info about the problem was embargoed until the talk and only Debian maintainers
were informed in advance.)

Milan

^ permalink raw reply	[flat|nested] 18+ messages in thread

end of thread, other threads:[~2016-12-07 13:00 UTC | newest]

Thread overview: 18+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-11-15 12:34 [dm-crypt] About CVE-2016-4484: - Cryptsetup Initrd root Shell Milan Broz
2016-11-15 13:27 ` Arno Wagner
2016-11-15 13:32 ` Sven Eschenberg
2016-11-15 15:18   ` Robert Nichols
2016-11-15 18:40     ` Sven Eschenberg
2016-11-15 19:19       ` Robert Nichols
2016-11-15 19:42         ` Sven Eschenberg
2016-11-15 22:51           ` Robert Nichols
2016-11-15 23:15           ` Michael Kjörling
2016-11-15 23:28             ` Sven Eschenberg
2016-11-15 23:52               ` Arno Wagner
2016-11-16  0:08                 ` Jonas Meurer
2016-11-16  1:15                   ` Sven Eschenberg
2016-11-16  7:32                     ` Milan Broz
2016-11-16 13:48                       ` Arno Wagner
2016-11-29 14:56                         ` David Niklas
2016-12-07 11:37 ` Jonas Meurer
2016-12-07 13:00   ` Arno Wagner

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox