Memory leak in Wireshark - CVE-2021-22173

 

Memory leak in Wireshark - CVE-2021-22173

Published: January 30, 2021 / Updated: February 1, 2021


Vulnerability identifier: #VU50148
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22173
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak within USB HID dissector. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

Wireshark
Gentoo Linux
Arch Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
Fedora
wireshark (Alpine package)
sbc-devel
sbc-debugsource
sbc-debuginfo
libsbc1
libsbc1-debuginfo
wireshark
libwireshark14-debuginfo
libwireshark14
wireshark-ui-qt-debuginfo
wireshark-ui-qt
wireshark-devel
wireshark-debugsource
wireshark-debuginfo
libwsutil12-debuginfo
libwsutil12
libwiretap11-debuginfo
libwiretap11
libvirt-daemon-driver-storage-disk
libvirt-daemon-qemu
libvirt-daemon-lxc
libvirt-daemon-hooks
libvirt-daemon-driver-storage-scsi-debuginfo
libvirt-daemon-driver-storage-scsi
libvirt-daemon-driver-storage-mpath-debuginfo
libvirt-daemon-driver-storage-mpath
libvirt-daemon-driver-storage-logical-debuginfo
libvirt-daemon-driver-storage-disk-debuginfo
libvirt-daemon-driver-storage-logical
libvirt-daemon-driver-storage-iscsi-debuginfo
libvirt-daemon-driver-storage-iscsi
libvirt-daemon-driver-qemu
libvirt-debugsource
libvirt-devel
libvirt-doc
libvirt-libs
libvirt-libs-debuginfo
libvirt-lock-sanlock
libvirt-lock-sanlock-debuginfo
libvirt-nss
libvirt-nss-debuginfo
libvirt-daemon-driver-libxl
libvirt-daemon-driver-libxl-debuginfo
libvirt-daemon-driver-storage-rbd
libvirt-daemon-driver-storage-rbd-debuginfo
libvirt-daemon-xen
libvirt-daemon-driver-storage-core
libvirt
libvirt-admin
libvirt-admin-debuginfo
libvirt-client
libvirt-client-debuginfo
libvirt-daemon
libvirt-daemon-config-network
libvirt-daemon-config-nwfilter
libvirt-daemon-debuginfo
libvirt-daemon-driver-interface
libvirt-daemon-driver-interface-debuginfo
libvirt-daemon-driver-lxc
libvirt-daemon-driver-network
libvirt-daemon-driver-storage-core-debuginfo
libvirt-daemon-driver-storage
libvirt-daemon-driver-secret-debuginfo
libvirt-daemon-driver-secret
libvirt-daemon-driver-qemu-debuginfo
libvirt-daemon-driver-nwfilter-debuginfo
libvirt-daemon-driver-nwfilter
libvirt-daemon-driver-nodedev-debuginfo
libvirt-daemon-driver-nodedev
libvirt-daemon-driver-network-debuginfo
libvirt-daemon-driver-lxc-debuginfo
libqt5-qtmultimedia-private-headers-devel
libQt5Multimedia5-debuginfo
libqt5-qtmultimedia-debugsource
libqt5-qtmultimedia-devel
libQt5Multimedia5

How to mitigate CVE-2021-22173

Install updates from vendor's website.

Wireshark - update to 3.4.3
wireshark (Alpine package) - update to 3.4.3-r0
sbc-devel - update to 1.3-3.2.1
sbc-debugsource - update to 1.3-3.2.1
sbc-debuginfo - update to 1.3-3.2.1
libsbc1 - update to 1.3-3.2.1
libsbc1-debuginfo - update to 1.3-3.2.1
wireshark - addressed in versions 3.4.3-1.fc32, 3.4.3-1.fc33
libwireshark14-debuginfo - update to 3.4.5-3.53.1
libwireshark14 - update to 3.4.5-3.53.1
wireshark-ui-qt-debuginfo - update to 3.4.5-3.53.1
wireshark-ui-qt - update to 3.4.5-3.53.1
wireshark-devel - update to 3.4.5-3.53.1
wireshark-debugsource - update to 3.4.5-3.53.1
wireshark-debuginfo - update to 3.4.5-3.53.1
wireshark - update to 3.4.5-3.53.1
libwsutil12-debuginfo - update to 3.4.5-3.53.1
libwsutil12 - update to 3.4.5-3.53.1
libwiretap11-debuginfo - update to 3.4.5-3.53.1
libwiretap11 - update to 3.4.5-3.53.1
libvirt-daemon-driver-storage-disk - update to 4.0.0-9.37.21
libvirt-daemon-qemu - update to 4.0.0-9.37.21
libvirt-daemon-lxc - update to 4.0.0-9.37.21
libvirt-daemon-hooks - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-scsi-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-scsi - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-mpath-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-mpath - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-logical-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-disk-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-logical - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-iscsi-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-iscsi - update to 4.0.0-9.37.21
libvirt-daemon-driver-qemu - update to 4.0.0-9.37.21
libvirt-debugsource - update to 4.0.0-9.37.21
libvirt-devel - update to 4.0.0-9.37.21
libvirt-doc - update to 4.0.0-9.37.21
libvirt-libs - update to 4.0.0-9.37.21
libvirt-libs-debuginfo - update to 4.0.0-9.37.21
libvirt-lock-sanlock - update to 4.0.0-9.37.21
libvirt-lock-sanlock-debuginfo - update to 4.0.0-9.37.21
libvirt-nss - update to 4.0.0-9.37.21
libvirt-nss-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-libxl - update to 4.0.0-9.37.21
libvirt-daemon-driver-libxl-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-rbd - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-rbd-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-xen - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-core - update to 4.0.0-9.37.21
libvirt - update to 4.0.0-9.37.21
libvirt-admin - update to 4.0.0-9.37.21
libvirt-admin-debuginfo - update to 4.0.0-9.37.21
libvirt-client - update to 4.0.0-9.37.21
libvirt-client-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon - update to 4.0.0-9.37.21
libvirt-daemon-config-network - update to 4.0.0-9.37.21
libvirt-daemon-config-nwfilter - update to 4.0.0-9.37.21
libvirt-daemon-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-interface - update to 4.0.0-9.37.21
libvirt-daemon-driver-interface-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-lxc - update to 4.0.0-9.37.21
libvirt-daemon-driver-network - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-core-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage - update to 4.0.0-9.37.21
libvirt-daemon-driver-secret-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-secret - update to 4.0.0-9.37.21
libvirt-daemon-driver-qemu-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-nwfilter-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-nwfilter - update to 4.0.0-9.37.21
libvirt-daemon-driver-nodedev-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-nodedev - update to 4.0.0-9.37.21
libvirt-daemon-driver-network-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-lxc-debuginfo - update to 4.0.0-9.37.21
libqt5-qtmultimedia-private-headers-devel - update to 5.9.7-7.2.1
libQt5Multimedia5-debuginfo - update to 5.9.7-7.2.1
libqt5-qtmultimedia-debugsource - update to 5.9.7-7.2.1
libqt5-qtmultimedia-devel - update to 5.9.7-7.2.1
libQt5Multimedia5 - update to 5.9.7-7.2.1

External References

Related Security Bulletins