[ANNOUNCE] cryptsetup 2.4.1

Milan Broz <[email protected]> Wed, 15 Sep 2021 11:58:44 +0200
Newsgroups gmane.linux.kernel.device-mapper.dm-crypt
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============7077270286312200004==
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="3424YGNyNSdSNAyujr2GAcbyMM7gf2Lfc"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--3424YGNyNSdSNAyujr2GAcbyMM7gf2Lfc
Content-Type: multipart/mixed; boundary="IAJ4OkIPp9zkmgH2prr6WQwgACtzjMYRZ";
 protected-headers="v1"
From: Milan Broz <[email protected]>
To: dm-crypt <[email protected]>
Message-ID: <23e036ba-bb02-1157-f5bc-63eb9a0eea7a-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
Subject: [ANNOUNCE] cryptsetup 2.4.1

--IAJ4OkIPp9zkmgH2prr6WQwgACtzjMYRZ
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

The cryptsetup 2.4.1 stable release is available at

     https://gitlab.com/cryptsetup/cryptsetup

Please note that release packages are located on kernel.org

     https://www.kernel.org/pub/linux/utils/cryptsetup/v2.4/

Feedback and bug reports are welcomed.

Cryptsetup 2.4.1 Release Notes
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D
Stable bug-fix release with minor extensions.

All users of cryptsetup 2.4.0 should upgrade to this version.

Changes since version 2.4.0
~~~~~~~~~~~~~~~~~~~~~~~~~~~

* Fix compilation for libc implementations without dlvsym().

  Some alternative libc implementations (like musl) do not provide
  versioned symbols dlvsym function. Code now fallbacks to dlsym
  operation for dynamic LUKS2 token load.
  It is up to maintainers to ensure that LUKS2 token plugins are
  compiled for the supported version.

* Fix compilation and tests on systems with non-standard libraries
  (standalone argp library, external gettext library, BusyBox
  implementations of standard tools).

* Try to workaround some issues on systems without udev support.
  NOTE: non-udev systems cannot provide all functionality for kernel
  device-mapper, and some operations can fail.

* Fixes for OpenSSL3 crypto backend (including FIPS mode).
  Because cryptsetup still requires some hash functions implemented
  in OpenSSL3 legacy provider, crypto backend now uses its library
  context and tries to load both default and legacy OpenSSL3 providers.

  If FIPS mode is detected, no library context is used, and it is up
  to the OpenSSL system-wide policy to load proper providers.

  NOTE: We still use some deprecated API in the OpenSSL3 backend,
  and there are some known problems in OpenSSL 3.0.0.

* Print error message when assigning a token to an inactive keyslot.

* Fix offset bug in LUKS2 encryption code if --offset option was used.

* Do not allow LUKS2 decryption for devices with data offset.
  Such devices cannot be used after decryption.

* Fix LUKS1 cryptsetup repair command for some specific problems.
  Repair code can now fix wrongly used initialization vector
  specification in ECB mode (that is insecure anyway!) and repair
  the upper-case hash specification in the LUKS1 header.


--IAJ4OkIPp9zkmgH2prr6WQwgACtzjMYRZ--

--3424YGNyNSdSNAyujr2GAcbyMM7gf2Lfc
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEKikYJD/eRmSNBob52bBXe9k+mPwFAmFBw9QACgkQ2bBXe9k+
mPxZIQ//R0KP7kgeI5+PShW7ytgETvHHGTfnPAaWDC85yzZvxKyGykSySYmdNeXM
vDKrqrD0r55wXXXOcCQeP1IkcuQOAPTZXJ3o8zCCwFG1o8wOC3y7Lre5Fl6tKCcG
efb3v63XUgZzd1+XiyViNXmp6YMLg6oMKb9nWP0/PBGRL4I+cBuAl8sQNNKXEUye
u9U1+UwZW4O+vxCeDiDqQvxtWu9vATDjGnPCVcg35eHGOVYIiPn7LGVDr09MbmNR
LuDijEkY5qXRuar3C5pSgN71XAs8nsBFZ8XnAPelgCCj2IIHSm+Lm6NP0CYlaAnh
OwSfJLi+7W0z3HEjIPfqrnlyc6+37DsqmQZi/eTZ44z3c36tDjZJKliAn7/Tgtnx
o+XC5YP1LrczY6osTvZmfuVtz6PO/wfrvQ7VVtO9M0AKauxH5fOjKo0hVXXWS0pw
BShMODwRyhSPJvlAkhRAYwQgGbFunBF1uuSoyH1guf1a+nH4p+XoMrG55CBoCA/L
ysL/rfqg40mWMVyxkGkC3V7+QfNDAtDYOMH+6wwJeXrXqr67vSRLE2f2PifFIEF4
kwVmVDFvsnQ2Qb96q8IyOfZJOfZ1I22w+rk51zhIYDu/7CQEvQL+WqHwzACNuuo5
I5bkMzJOLh5NaCbNxrFzGiyy8i3ozT15WvUbEJip5V5vt1amm9A=
=dG9R
-----END PGP SIGNATURE-----

--3424YGNyNSdSNAyujr2GAcbyMM7gf2Lfc--

--===============7077270286312200004==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
dm-crypt mailing list -- [email protected]
To unsubscribe send an email to [email protected]

--===============7077270286312200004==--