Infinite loop in GNU C Library (glibc) - CVE-2020-27618

 

Infinite loop in GNU C Library (glibc) - CVE-2020-27618

Published: January 4, 2021 / Updated: September 23, 2024


Vulnerability identifier: #VU50404
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27618
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within iconv implementation when processing multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, IBM1399 encodings. A remote attacker can pass specially crafted data to the application, consume all available system resources and cause denial of service conditions.


Affected software

GNU C Library (glibc)
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Server 11
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
Ubuntu
SIMATIC S7-1500 TM MFP - BIOS
Isolation Segment
VMware Tanzu Application Service for VMs
Service Telemetry Framework
Netcool Operations Insight
IBM Cloud Transformation Advisor
BIG-IP
cflinuxfs3
Tanzu Greenplum for Kubernetes
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
VMware Tanzu Operations Manager
Cloud Pak for Security (CP4S)
RecoverPoint for Virtual Machines
Oracle Communications Cloud Native Core Service Communication Proxy
Red Hat OpenShift Jaeger
BIG-IQ Centralized Management
IBM Security Verify Access
libc6 (Ubuntu package)
glibc-profile
glibc-locale-32bit
glibc-info
glibc-i18ndata
glibc-32bit
glibc
glibc-devel
glibc-locale
glibc-html
nscd
glibc-debuginfo
glibc-profile-32bit
glibc-debuginfo-32bit
glibc-debugsource
glibc-devel-32bit
glibc-devel-static
nscd-debuginfo
glibc-locale-debuginfo
glibc-devel-debuginfo-32bit
glibc-devel-debuginfo
glibc-locale-debuginfo-32bit
glibc-locale-base-debuginfo
glibc-locale-base
glibc-extra-debuginfo
glibc-extra
glibc-locale-base-32bit-debuginfo
glibc-utils
glibc-utils-debuginfo
glibc-utils-src-debugsource
glibc-32bit-debuginfo
glibc-locale-base-32bit
glibc-devel-32bit-debuginfo
glibc (Red Hat package)
IBM Integrated Analytics System
Web Terminal
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)

How to mitigate CVE-2020-27618

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

BIG-IP - addressed in versions 15.1.9, 16.1.5
cflinuxfs3 - update to 0.275.0
Red Hat OpenShift Serverless - update to 1.16.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
libc6 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.27-3ubuntu1.5, 2.31-0ubuntu9.7, 2.34-0ubuntu3.2
IBM Integrated Analytics System - update to 1.0.30.0
Web Terminal - update to 1.3
Netcool Operations Insight - update to 1.6.8
Tanzu Greenplum for Kubernetes - update to 2.0.0
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
VMware Tanzu Operations Manager - update to 2.10.52
glibc-profile - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-locale-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1
glibc-info - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-i18ndata - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-devel - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-locale - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-html - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1
nscd - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-debuginfo - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-profile-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1
glibc-debuginfo-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1
glibc-debugsource - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-devel-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-devel-static - addressed in versions 2.22-114.8.3, 2.26-13.56.1
nscd-debuginfo - addressed in versions 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-locale-debuginfo - addressed in versions 2.22-114.8.3, 2.22-126.1
glibc-devel-debuginfo-32bit - addressed in versions 2.22-114.8.3, 2.22-126.1
glibc-devel-debuginfo - addressed in versions 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-locale-debuginfo-32bit - addressed in versions 2.22-114.8.3, 2.22-126.1
glibc-locale-base-debuginfo - update to 2.26-13.56.1
glibc-locale-base - update to 2.26-13.56.1
glibc-extra-debuginfo - update to 2.26-13.56.1
glibc-extra - update to 2.26-13.56.1
glibc-locale-base-32bit-debuginfo - update to 2.26-13.56.1
glibc-utils - update to 2.26-13.56.1
glibc-utils-debuginfo - update to 2.26-13.56.1
glibc-utils-src-debugsource - update to 2.26-13.56.1
glibc-32bit-debuginfo - update to 2.26-13.56.1
glibc-locale-base-32bit - update to 2.26-13.56.1
glibc-devel-32bit-debuginfo - update to 2.26-13.56.1
glibc (Red Hat package) - update to 2.28-151.el8
IBM Cloud Transformation Advisor - update to 3.10.0
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Robotic Process Automation for Cloud Pak - update to 21.0.6

External References

Related Security Bulletins