Re: [oss-security] CVE-2016-4484: – Cryptsetup Initrd root Shell

Posted by Jason Cooper on Nov 16

Hi Hector,

This wording appears to have caused a lot of misunderstanding. afaict,
the binary executable ‘cryptsetup’ has nothing to do with this bug.
Rather, it is completely in the initrd’s script for decrypting a
partition containing the rootfs.

On Debian based systems, the initrd script is in the cryptsetup package,
but if one looks at the upstream repository for cryptsetup:

https://gitlab.com/cryptsetup/cryptsetup.git

Leave a Reply