[ANNOUNCE] cryptsetup 2.3.6

Milan Broz <[email protected]> Fri, 28 May 2021 12:37:35 +0200
Newsgroups gmane.linux.kernel.device-mapper.dm-crypt
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============6233065164538698138==
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="S7GeazNw1e5WETcj4lslMCUkIsN0IkWUr"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--S7GeazNw1e5WETcj4lslMCUkIsN0IkWUr
Content-Type: multipart/mixed; boundary="q0PENJeXBc7I0i4cIU4LcMnNMDFED6lzK";
 protected-headers="v1"
From: Milan Broz <[email protected]>
To: dm-crypt <[email protected]>
Message-ID: <3309213d-b68d-e7e0-eef3-ce5cee0eef22-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
Subject: [ANNOUNCE] cryptsetup 2.3.6

--q0PENJeXBc7I0i4cIU4LcMnNMDFED6lzK
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

The cryptsetup 2.3.6 stable release is available at

     https://gitlab.com/cryptsetup/cryptsetup

Please note that release packages are located on kernel.org

     https://www.kernel.org/pub/linux/utils/cryptsetup/v2.3/

Feedback and bug reports are welcomed.

Cryptsetup 2.3.6 Release Notes
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D
Stable bug-fix release with minor extensions.

All users of cryptsetup 2.x and later should upgrade to this version.

Changes since version 2.3.5
~~~~~~~~~~~~~~~~~~~~~~~~~~~

* integritysetup: Fix possible dm-integrity mapping table truncation.

  While integritysetup in standalone mode (no encryption) was not
  designed to provide keyed (and cryptographically strong) data
  integrity protection, some options can use such algorithms (HMAC).

  If a key is used, it is directly sent to the kernel dm-integrity as
  a mapping table option (no key derivation is performed).
  For HMAC, such a key could be quite long (up to 4096 bytes in
  integritysetup CLI).

  Unfortunately, due to fixed buffers and not correctly checking string
  truncation, some parameter combinations could cause truncation
  of the dm-integrity mapping table.
  In most cases, the table was rejected by the kernel.
  The worst possible case was key truncation for HMAC options
  (internal_hash and journal_mac dm-integrity table options).

  This release fixes possible truncation and also adds more sanity
  checks to reject truncated options.
  Also, integritysetup now mentions maximal allowed key size
  in --help output.

  For old standalone dm-integrity devices where the key length was
  truncated, you have to modify (shorten) --integrity-key-size
  resp. --journal-integrity-key-size option now.

  This bug is _not_ present for dm-crypt/LUKS, LUKS2 (including
  integrity protection), or dm-verity devices; it affects only
  standalone dm-integrity with HMAC integrity protection.

* cryptsetup: Backup header can be used to activate TCRYPT device.
  Use --header option to specify the header.

* cryptsetup: Avoid LUKS2 decryption without detached header.
  This feature will be added later and is currently not supported.

* Additional fixes and workarounds for common warnings produced
  by some static analysis tools (like gcc-11 analyzer) and additional
  code hardening.

* Fix standalone libintl detection for compiled tests.

* Add Blake2b and Blake2s hash support for crypto backends.
  Kernel and gcrypt crypto backend support all variants.
  OpenSSL supports only Blake2b-512 and Blake2s-256.
  Crypto backend supports kernel notation e.g. "blake2b-512".


--q0PENJeXBc7I0i4cIU4LcMnNMDFED6lzK--

--S7GeazNw1e5WETcj4lslMCUkIsN0IkWUr
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEKikYJD/eRmSNBob52bBXe9k+mPwFAmCwx/AACgkQ2bBXe9k+
mPxo3hAAl71gkG5Bo0OhMVgOLNHSitQugcrzf61wto27lLA1pVKswF5f7rhsYcCx
I92COydLEGQ23I2YnNsqmuJt4l9xXSxgRvQPvucKUdqfoviBy6+VAH/6FAK8JP7H
MaUdtnsw6TayYCf/Op4yX9Dk7zKbzaS/u7EUYAHEZEAvgpL65KblQdt1ZZZ2ZidW
3tx/nHdgAcLAEGIK0eikxrpKUAZK1u4StzCInzt2XH0wo+PNN199hGvvcOVwz2M1
rsJIoUAEqbCzxWAAZdeScpubq2ROf4gVELKYtDs7/fHIWih8/9LfZRNI5Ib4NG6Z
b2RyZG1uaJOKyMFkbHqSjlygGbBG4RfCSTZHSL1BxtgZ1K5CR6JdAY+WSQ+lO/6B
pD/vmph3jM4Wzu+LviJS/wfoWrC85kFpsD1/Hvm2CPHYQCavdkEUDmbqu2979KoG
8YDEBAUCFM7L+KRk9bO4CUCMc33tQcM81oiWlSsf6dXmK3nqD7BP3YCdvwkFMEAA
yf9sXDAp+ZZihitb5fjRNXUiXE0lNR1M2vWOl9CeQVKhpuCF61m2nu4JDEdf9A3/
3oMZOOhY3ZSd28ViF8Be8cahrXgte+ABhLf1JNqSP21XBG+jVFmoZQIzirF6l/sZ
On4bytlQWc0hk3mLKjW9rGg4QIvuwmsl7H1j9iD1pIwKxVM1xjc=
=UUe1
-----END PGP SIGNATURE-----

--S7GeazNw1e5WETcj4lslMCUkIsN0IkWUr--

--===============6233065164538698138==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
dm-crypt mailing list -- [email protected]
To unsubscribe send an email to [email protected]

--===============6233065164538698138==--