stable

calamares-2.4.4-5.fc24

FEDORA-2016-5c7e9b8778 created by kkofler 8 years ago for Fedora 24

A security update that fixes Calamares bug CAL-405: https://calamares.io/bugs/browse/CAL-405

When installing with a LUKS-encrypted / partition, Calamares was always creating a keyfile to decode / and storing it in the initramfs. It did that even with an unencrypted separate /boot partition. As a result, the keyfile would be stored in cleartext on the /boot partition, and it was possible to unlock the / partition without ever entering a passphrase. This completely defeated the security of LUKS.

Please note that this only affects manual partitioning. The automatic partitioning never leaves /boot unencrypted (and it is, in fact, recommended to also always encrypt /boot when doing manual partitioning).

This update fixes the dracutlukscfg module to not add the keyfile to install_items in the dracut configuration (so that dracut will not include it onto the initramfs) if /boot is separate and unencrypted.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2016-5c7e9b8778

This update has been submitted for testing by kkofler.

8 years ago

kkofler edited this update.

8 years ago

This update has been pushed to testing.

8 years ago
User Icon ngompa provided feedback 8 years ago
karma

This update has been submitted for stable by kkofler.

8 years ago

This update has been pushed to stable.

8 years ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
8 years ago
in testing
8 years ago
in stable
8 years ago
modified
8 years ago

Automated Test Results