CVE-2021-4122
published 2022-08-24CVE-2021-4122: It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical…
PriorityP418medium4.3CVSS 3.1
AVPACLPRNUIRSUCNIHAN
EPSS
0.28%
20.2th percentile
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cryptsetup_project | cryptsetup | < 2.3.7 | 2.3.7 |
| cryptsetup_project | cryptsetup | — | — |
| cryptsetup_project | cryptsetup | >= 0 < 2:2.3.7-1+deb11u1 | 2:2.3.7-1+deb11u1 |
| cryptsetup_project | cryptsetup | >= 0 < 2:2.4.3-1 | 2:2.4.3-1 |
| cryptsetup_project | cryptsetup | >= 0 < 2:2.4.3-1 | 2:2.4.3-1 |
| cryptsetup_project | cryptsetup | >= 0 < 2:2.4.3-1 | 2:2.4.3-1 |
| cryptsetup_project | cryptsetup | >= 2.4.0 < 2.4.3 | 2.4.3 |
| debian | cryptsetup | < cryptsetup 2:2.4.3-1 (bookworm) | cryptsetup 2:2.4.3-1 (bookworm) |
| msrc | cm1_cryptsetup_2.3.7-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Microsoft
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium such as a flash dis
vendor_msrc·2022-08-09·CVSS 4.3
CVE-2021-4122 [MEDIUM] CWE-345 It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium such as a flash dis
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium such as a flash disk could use this flaw to force a user into permanently disabling the encryption layer of that medium.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See th
Ubuntu
cryptsetup vulnerability
vendor_ubuntu·2022-02-15
CVE-2021-4122 cryptsetup vulnerability
Title: cryptsetup vulnerability
Summary: cryptsetup could be made to expose sensitive information.
Milan Broz discovered that cryptsetup incorrectly handled LUKS2
reencryption recovery. An attacker with physical access to modify the
encrypted device header may trigger the device to be unencrypted the next
time it is mounted by the user.
On Ubuntu 20.04 LTS, this issue was fixed by disabling the online
reencryption feature.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cryptsetup: disable encryption via header rewrite
vendor_redhat·2022-01-13·CVSS 4.3
CVE-2021-4122 [MEDIUM] CWE-349 cryptsetup: disable encryption via header rewrite
cryptsetup: disable encryption via header rewrite
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
Statement: Red Hat Enterprise Linux version 7 and older are not affected since they do not support online reencryption.
Package: cryptsetu
Debian
CVE-2021-4122: cryptsetup - It was found that a specially crafted LUKS header could trick cryptsetup into di...
vendor_debian·2021·CVSS 4.3
CVE-2021-4122 [MEDIUM] CVE-2021-4122: cryptsetup - It was found that a specially crafted LUKS header could trick cryptsetup into di...
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
Scope: local
bookworm: resolved (fixed in 2:2.4.3-1)
bullseye: resolved (fixed in 2:2.3.7-1+deb11u1)
forky: resolved (fixed in 2:2.4.3-1)
sid: resolved (fixed in 2:2.4.3-1)
trixie: resolved (fixed in 2:2.4.3-1)
GHSA
GHSA-8fgw-wvm8-3x84: It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device
ghsa_unreviewed·2022-08-25
CVE-2021-4122 [MEDIUM] CWE-345 GHSA-8fgw-wvm8-3x84: It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
OSV
CVE-2021-4122: It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device
osv·2022-08-24·CVSS 4.3
CVE-2021-4122 [MEDIUM] CVE-2021-4122: It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
No detection rules found.
No public exploits indexed.
Trailofbits
Vulnerabilities in LUKS2 disk encryption for confidential VMs
blogs_trailofbits·2025-10-30·CVSS 8.3
[HIGH] Vulnerabilities in LUKS2 disk encryption for confidential VMs
Trail of Bits is disclosing vulnerabilities in eight different confidential computing systems that use Linux Unified Key Setup version 2 (LUKS2) for disk encryption. Using these vulnerabilities, a malicious actor with access to storage disks can extract all confidential data stored on that disk and can modify the contents of the disk arbitrarily. The vulnerabilities are caused by malleable metadata headers that allow an attacker to trick a trusted execution environment guest into encrypting secret data with a null cipher.
The following CVEs are associated with this disclosure:
CVE-2025-59054
CVE-2025-58356
This is a coordinated disclosure; we have notified the following projects, which remediated the issues prior to our publication.
oasis-sdk
dstack
tdx-init
secret-vm-ops
salmiac
Trailofbits
Vulnerabilities in LUKS2 disk encryption for confidential VMs
blogs_trailofbits·2025-10-30·CVSS 8.3
[HIGH] Vulnerabilities in LUKS2 disk encryption for confidential VMs
Trail of Bits is disclosing vulnerabilities in eight different confidential computing systems that use Linux Unified Key Setup version 2 (LUKS2) for disk encryption. Using these vulnerabilities, a malicious actor with access to storage disks can extract all confidential data stored on that disk and can modify the contents of the disk arbitrarily. The vulnerabilities are caused by malleable metadata headers that allow an attacker to trick a trusted execution environment guest into encrypting secret data with a null cipher.
The following CVEs are associated with this disclosure:
- CVE-2025-59054
- CVE-2025-58356
This is a coordinated disclosure; we have notified the following projects, which remediated the issues prior to our publication.
- Oasis Protocol: oasis-sdk (v0.7.2)
- Phala Netwo
https://access.redhat.com/security/cve/CVE-2021-4122https://bugzilla.redhat.com/show_bug.cgi?id=2031859https://bugzilla.redhat.com/show_bug.cgi?id=2032401https://gitlab.com/cryptsetup/cryptsetup/-/commit/0113ac2d889c5322659ad0596d4cfc6da53e356chttps://mirrors.edge.kernel.org/pub/linux/utils/cryptsetup/v2.4/v2.4.3-ReleaseNoteshttps://access.redhat.com/security/cve/CVE-2021-4122https://bugzilla.redhat.com/show_bug.cgi?id=2031859https://bugzilla.redhat.com/show_bug.cgi?id=2032401https://gitlab.com/cryptsetup/cryptsetup/-/commit/0113ac2d889c5322659ad0596d4cfc6da53e356chttps://mirrors.edge.kernel.org/pub/linux/utils/cryptsetup/v2.4/v2.4.3-ReleaseNotes
2022-08-24
Published