Memory leak in ConnMan - CVE-2021-26676
Published: February 12, 2021
Vulnerability identifier: #VU50669
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-26676
CWE-ID: CWE-401
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due memory leak in gdhcp in ConnMan. A remote attacker on the local network can force the application to leak sensitive stack information.
Affected software
ConnMan
Arch Linux
Gentoo Linux
Ubuntu
connman (Debian package)
connman (Ubuntu package)
Arch Linux
Gentoo Linux
Ubuntu
connman (Debian package)
connman (Ubuntu package)
How to mitigate CVE-2021-26676
Install updates from vendor's website.
ConnMan - update to 1.39
connman (Debian package) - update to 1.36-2.1~deb10u1
connman (Ubuntu package) - addressed in versions Ubuntu Pro, 1.36-2ubuntu0.1, 1.36-2.3ubuntu0.1, 1.41-2ubuntu0.23.04.1
connman (Debian package) - update to 1.36-2.1~deb10u1
connman (Ubuntu package) - addressed in versions Ubuntu Pro, 1.36-2ubuntu0.1, 1.36-2.3ubuntu0.1, 1.41-2ubuntu0.23.04.1
External References
- https://bugzilla.suse.com/show_bug.cgi?id=1181751
- https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?id=58d397ba74873384aee449690a9070bacd5676fa
- https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?id=a74524b3e3fad81b0fd1084ffdf9f2ea469cd9b1
- https://git.kernel.org/pub/scm/network/connman/connman.git/tree/ChangeLog
- https://lists.debian.org/debian-lts-announce/2021/02/msg00013.html
- https://www.debian.org/security/2021/dsa-4847
- https://www.openwall.com/lists/oss-security/2021/02/08/2