A world full of brilliant cryptographers outraged at the NSA, trying to get the NSA off the IETF crypto review board, working on publishing results about NSA-sponsored crypto... and you want to talk about the MD2 and RC2 constants? What's the largest system that ever relied on MD2? Let's start there.
You are obviously right. Now I feel dumb. I concede the importance of MD2.
Do you believe that the starting state for MD2 is a possible backdoor?
Later: I'm batting .000 today on this stuff; it's not the starting state of MD2 that he's talking about, of course, and the misapprehension that he was is part of why I was dismissive. Go me.
It seems your edit did all the work for me. Being in the core of the MD2 compression function puts the Sbox in a good place to be a backdoor.
However I strongly doubt this is one. The attacks that have broken MD2 do not seem to hinge terribly on the Sbox (I may be wrong, it was only a cursory look). It's more likely to me that the Sbox was generated using a hard-to-replicate Knuth shuffle using the digits of Pi.
CBC bitflipping is in set #2. Incidentally, somewhere in the mists of time is a very weird blog post ("If You're Typing The Letters A-E-S Into Your Code, You're Doing It Wrong") I wrote describing how to implement this attack --- though not against LUKS.