UNIX symbolic link following in Gnome GLib - CVE-2021-28153

 

UNIX symbolic link following in Gnome GLib - CVE-2021-28153

Published: March 15, 2021


Vulnerability identifier: #VU51454
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28153
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue, when g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


Affected software

Gnome GLib
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Ubuntu
openEuler
Fedora
Cloud Pak for Security (CP4S)
Dell EMC NetWorker vProxy
Dell Secure Connect Gateway
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Migration Toolkit for Containers
Red Hat OpenShift Serverless
glib2
libglib2.0-0 (Ubuntu package)
libgmodule-2_0-0
libgthread-2_0-0-32bit
libgmodule-2_0-0-32bit
libgmodule-2_0-0-debuginfo
libgmodule-2_0-0-debuginfo-32bit
libgobject-2_0-0
libgobject-2_0-0-32bit
libgobject-2_0-0-debuginfo
libgobject-2_0-0-debuginfo-32bit
libgthread-2_0-0
libgthread-2_0-0-debuginfo
libgthread-2_0-0-debuginfo-32bit
libglib-2_0-0-debuginfo
glib2-lang
glib2-debugsource
libglib-2_0-0-debuginfo-32bit
glib2-tools
glib2-tools-debuginfo
libgio-2_0-0
libgio-2_0-0-debuginfo
libgio-2_0-0-debuginfo-32bit
libglib-2_0-0
libglib-2_0-0-32bit
libgio-2_0-0-32bit
glib2-devel
glib2-devel-debuginfo
libgmodule-2_0-0-32bit-debuginfo
libgio-2_0-0-32bit-debuginfo
libglib-2_0-0-32bit-debuginfo
libgobject-2_0-0-32bit-debuginfo
glib2 (Red Hat package)
glib2-debuginfo
glib2-help
gio-branding-upstream
libgthread-2_0-0-32bit-debuginfo
glib2-devel-static
libgio-fam-32bit-debuginfo
libgio-fam-32bit
libgio-fam-debuginfo
libgio-fam
glib2-tests-debuginfo
glib2-tests
glib2-tools-32bit-debuginfo
glib2-devel-32bit-debuginfo
glib2-devel-32bit
glib2-tools-32bit
mingw-glib2
mingw-glib2 (Red Hat package)
EMC ECS
EMC Cloud Tiering Appliance
Dell EMC VxRail Appliance

How to mitigate CVE-2021-28153

Install updates from vendor's website.

Gnome GLib - update to 2.67.6
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Dell EMC NetWorker vProxy - update to 4.3.0-32
Dell Secure Connect Gateway - update to 5.12.00.10
Migration Toolkit for Containers - update to 1.5.4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
glib2 - update to 2.36.3-5.23
libglib2.0-0 (Ubuntu package) - addressed in versions 2.48.2-0ubuntu4.8, 2.56.4-0ubuntu0.18.04.8, 2.64.6-1~ubuntu20.04.3, 2.66.1-2ubuntu0.2
libgmodule-2_0-0 - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgthread-2_0-0-32bit - addressed in versions 2.48.2-12.28.1, 2.62.6-150200.3.9.1
libgmodule-2_0-0-32bit - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgmodule-2_0-0-debuginfo - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgmodule-2_0-0-debuginfo-32bit - update to 2.48.2-12.28.1
libgobject-2_0-0 - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgobject-2_0-0-32bit - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgobject-2_0-0-debuginfo - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgobject-2_0-0-debuginfo-32bit - update to 2.48.2-12.28.1
libgthread-2_0-0 - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgthread-2_0-0-debuginfo - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgthread-2_0-0-debuginfo-32bit - update to 2.48.2-12.28.1
libglib-2_0-0-debuginfo - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
glib2-lang - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
glib2-debugsource - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libglib-2_0-0-debuginfo-32bit - update to 2.48.2-12.28.1
glib2-tools - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
glib2-tools-debuginfo - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgio-2_0-0 - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgio-2_0-0-debuginfo - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgio-2_0-0-debuginfo-32bit - update to 2.48.2-12.28.1
libglib-2_0-0 - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libglib-2_0-0-32bit - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgio-2_0-0-32bit - addressed in versions 2.48.2-12.28.1, 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
glib2-devel - addressed in versions 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
glib2-devel-debuginfo - addressed in versions 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgmodule-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgio-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libglib-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
libgobject-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-150000.4.29.1, 2.62.6-150200.3.9.1
glib2 (Red Hat package) - update to 2.56.4-156.el8
glib2-debugsource - update to 2.62.5-7
glib2 - update to 2.62.5-7
glib2-debuginfo - update to 2.62.5-7
glib2-devel - update to 2.62.5-7
glib2-help - update to 2.62.5-7
gio-branding-upstream - update to 2.62.6-150200.3.9.1
libgthread-2_0-0-32bit-debuginfo - update to 2.62.6-150200.3.9.1
glib2-devel-static - update to 2.62.6-150200.3.9.1
libgio-fam-32bit-debuginfo - update to 2.62.6-150200.3.9.1
libgio-fam-32bit - update to 2.62.6-150200.3.9.1
libgio-fam-debuginfo - update to 2.62.6-150200.3.9.1
libgio-fam - update to 2.62.6-150200.3.9.1
glib2-tests-debuginfo - update to 2.62.6-150200.3.9.1
glib2-tests - update to 2.62.6-150200.3.9.1
glib2-tools-32bit-debuginfo - update to 2.62.6-150200.3.9.1
glib2-devel-32bit-debuginfo - update to 2.62.6-150200.3.9.1
glib2-devel-32bit - update to 2.62.6-150200.3.9.1
glib2-tools-32bit - update to 2.62.6-150200.3.9.1
glib2 - update to 2.66.8-1.fc33
mingw-glib2 - update to 2.66.8-1.fc33
mingw-glib2 (Red Hat package) - update to 2.70.1-2.el9
EMC ECS - update to 3.8.0.2
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell EMC VxRail Appliance - update to 7.0.411
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins