Comment 1 for bug 1660701

Revision history for this message
Tyler Hicks (tyhicks) wrote :

Hello Mark - Thanks for the bug report! We are aware of this flaw in cryptsetup and have triaged it in the Ubuntu CVE Tracker:

  http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-4484.html

We marked it as a low priority issue as there are several other ways that you can get a root shell during the boot process. We don't plan to put out security updates to our stable releases for this issue by itself. However, we will include this fix if there is a more urgent cryptsetup security issue that we address in the future.