Candidate: CVE-2004-2136 References: http://marc.theaimsgroup.com/?l=linux-kernel&m=107719798631935&w=2 http://mareichelt.de/pub/notmine/diskenc.pdf http://www.securiteam.com/exploits/5UP0P1PFPM.html Description: dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption. Notes: jmm> IIRC there was some serious flaming about the different disk encryption systems, jmm> I'm not sure whether this has been addressed or how real it is jmm> 2.4 doesn't have dm-crypt, though Bugs: upstream: linux-2.6: 2.6.8-sarge-security: ignored (2.6.8-16sarge5) 2.4.27-sarge-security: N/A 2.6.18-etch-security: ignored