It was found that a specially crafted LUKS header could...
Moderate severity
Unreviewed
Published
Aug 25, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Aug 24, 2022
Published to the GitHub Advisory Database
Aug 25, 2022
Last updated
Feb 3, 2023
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
References