Incorrect Conversion between Numeric Types in Gnome GLib - CVE-2021-27218
Published: March 15, 2021
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to incorrect conversion between numeric types in Gnome Glib. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.
Affected software
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE MicroOS
SUSE Enterprise Storage
SUSE OpenStack Cloud
Anolis OS
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
cflinuxfs3
Xenial Stemcells
Service Telemetry Framework
Red Hat Advanced Cluster Management for Kubernetes
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
Red Hat Container Native Virtualization
OpenShift Virtualization
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
IBM Security Verify Access
CF Deployment
IBM Integrated Analytics System
libglib2.0-0 (Ubuntu package)
libgio-fam
libgio-2_0-0-debuginfo-32bit
libgio-2_0-0-debuginfo
libgio-2_0-0-32bit
libgio-2_0-0
glib2-tools-debuginfo
glib2-tools
glib2-debugsource
libgthread-2_0-0-debuginfo-32bit
glib2-lang
libgmodule-2_0-0
libgio-fam-debuginfo
glib2-devel
glib2-devel-debuginfo
glib2-devel-static
libglib-2_0-0
libglib-2_0-0-32bit
libglib-2_0-0-debuginfo
libglib-2_0-0-debuginfo-32bit
libgmodule-2_0-0-32bit
libgmodule-2_0-0-debuginfo
libgmodule-2_0-0-debuginfo-32bit
libgobject-2_0-0
libgobject-2_0-0-32bit
libgobject-2_0-0-debuginfo
libgobject-2_0-0-debuginfo-32bit
libgthread-2_0-0
libgthread-2_0-0-32bit
libgthread-2_0-0-debuginfo
libgobject-2_0-0-32bit-debuginfo
libgmodule-2_0-0-32bit-debuginfo
libglib-2_0-0-32bit-debuginfo
libgio-2_0-0-32bit-debuginfo
glib2-tests
glib2
glib2-fam
glib2 (Red Hat package)
glib2-help
glib2-debuginfo
mingw-glib2
mingw-glib2 (Red Hat package)
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
How to mitigate CVE-2021-27218
cflinuxfs3 - update to 0.228.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - update to 1.20.5
Red Hat OpenShift Container Platform - update to 4.7.28
CF Deployment - update to 16.7.0
IBM Integrated Analytics System - update to 1.0.30.0
Migration Toolkit for Containers - update to 1.5.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.2
OpenShift Virtualization - addressed in versions 2.6.7, 4.8.1, 4.8.2
libglib2.0-0 (Ubuntu package) - addressed in versions 2.48.2-0ubuntu4.7, 2.56.4-0ubuntu0.18.04.7, 2.64.6-1~ubuntu20.04.2, 2.66.1-2ubuntu0.1
libgio-fam - update to 2.48.2-12.22.1
libgio-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
libgio-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgio-2_0-0-32bit - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgio-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-tools-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-tools - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-debugsource - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgthread-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
glib2-lang - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgmodule-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgio-fam-debuginfo - update to 2.48.2-12.22.1
glib2-devel - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-devel-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-devel-static - update to 2.48.2-12.22.1
libglib-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libglib-2_0-0-32bit - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libglib-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libglib-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
libgmodule-2_0-0-32bit - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgmodule-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgmodule-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
libgobject-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgobject-2_0-0-32bit - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgobject-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgobject-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
libgthread-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgthread-2_0-0-32bit - update to 2.48.2-12.22.1
libgthread-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgobject-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-4.24.1, 2.62.6-3.6.1
libgmodule-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-4.24.1, 2.62.6-3.6.1
libglib-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-4.24.1, 2.62.6-3.6.1
libgio-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-tests - update to 2.56.4-10
glib2 - update to 2.56.4-10
glib2-devel - update to 2.56.4-10
glib2-fam - update to 2.56.4-10
glib2 (Red Hat package) - update to 2.56.4-10.el8_4.1
glib2 - addressed in versions 2.62.5-4, 2.62.5-6
glib2-help - addressed in versions 2.62.5-4, 2.62.5-6
glib2-devel - addressed in versions 2.62.5-4, 2.62.5-6
glib2-debugsource - addressed in versions 2.62.5-4, 2.62.5-6
glib2-debuginfo - addressed in versions 2.62.5-4, 2.62.5-6
mingw-glib2 - addressed in versions 2.66.7-1.fc33, 2.66.7-1.fc34
mingw-glib2 (Red Hat package) - update to 2.66.7-2.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC VxRail Appliance - update to 7.0.240
Xenial Stemcells - addressed in versions 456.150, 621.113
External References
Related Security Bulletins
- Security restrictoins bypass in GNOME GLib
- Multiple vulnerabilities in Cloud Foundry products
- Gentoo update for GLib
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers
- Multiple vulnerabilities in OpenShift Container Platform 4.7
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in OpenShift Virtualization
- Red Hat Enterprise Linux 8 update for mingw-glib2
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in IBM Security Verify Access
- Ubuntu update for glib2.0
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Red Hat Enterprise Linux 8 update for glib2
- SUSE update for glib2
- SUSE update for glib2
- SUSE update for glib2
- openEuler 20.03 LTS SP1 update for glib2
- Multiple vulnerabilities in IBM Integrated Analytics System
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Fedora 33 update for mingw-glib2
- Fedora 34 update for mingw-glib2
- openEuler 20.03 LTS update for glib2
- Anolis OS update for glib2