Integer overflow in Gnome GLib - CVE-2021-27219
Published: March 15, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to integer overflow within the g_bytes_new() function on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. A local user can run a specially crafted program to trigger an integer overflow and execute arbitrary code with elevated privileges.
Affected software
Gentoo Linux
Amazon Linux AMI
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Manager Server
SUSE MicroOS
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
SUSE Enterprise Storage
Red Hat Enterprise Linux Server
CentOS
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
SUSE OpenStack Cloud
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Anolis OS
Red Hat CodeReady Linux Builder for x86_64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
cflinuxfs3
Xenial Stemcells
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
Red Hat Virtualization
OpenShift Virtualization
Migration Toolkit for Containers
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
glib2 (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
libglib2.0-0 (Ubuntu package)
libgio-2_0-0
libgio-2_0-0-32bit
libgthread-2_0-0-32bit
libgio-2_0-0-debuginfo
glib2-tools-debuginfo
glib2-tools
glib2-debugsource
libgthread-2_0-0-debuginfo
libgthread-2_0-0-debuginfo-32bit
glib2-lang
libgio-fam
libgio-fam-debuginfo
glib2-devel
glib2-devel-debuginfo
glib2-devel-static
libglib-2_0-0
libgthread-2_0-0
libgobject-2_0-0-debuginfo-32bit
libgobject-2_0-0-debuginfo
libgobject-2_0-0-32bit
libgobject-2_0-0
libgmodule-2_0-0-debuginfo-32bit
libgmodule-2_0-0-debuginfo
libgmodule-2_0-0-32bit
libgmodule-2_0-0
libglib-2_0-0-debuginfo-32bit
libglib-2_0-0-debuginfo
libglib-2_0-0-32bit
libgio-2_0-0-debuginfo-32bit
libgobject-2_0-0-32bit-debuginfo
libgmodule-2_0-0-32bit-debuginfo
libglib-2_0-0-32bit-debuginfo
libgio-2_0-0-32bit-debuginfo
glib2
glib2-tests
glib2-fam
glib2-help
glib2-debuginfo
mingw-glib2
mingw-glib2 (Red Hat package)
Red Hat Virtualization Host
Web Terminal
OpenShift Logging
IBM Elastic Storage System
IBM Security Verify Access
CF Deployment
IBM Integrated Analytics System
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
How to mitigate CVE-2021-27219
cflinuxfs3 - update to 0.228.0
Red Hat OpenShift Serverless - update to 1.16.0
Migration Toolkit for Containers - update to 1.4.6
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
glib2 (Red Hat package) - addressed in versions 2.28.8-11.el6_10, 2.42.2-6.el7_2, 2.46.2-5.el7_3, 2.50.3-4.el7_4, 2.56.1-5.el7_6, 2.56.1-6.el7_7, 2.56.1-9.el7_9, 2.56.4-8.el8_1, 2.56.4-8.el8_2.1, 2.56.4-10.el8_4
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.16-1.el7ev, 4.4.6-2.el8ev
redhat-virtualization-host (Red Hat package) - addressed in versions 4.3.16-20210615.0.el7_9, 4.4.6-20210615.0.el8_4
OpenShift Logging - update to 5.0.5
IBM Elastic Storage System - addressed in versions 6.0.2.2, 6.1.1.1
CF Deployment - update to 16.7.0
IBM Integrated Analytics System - update to 1.0.30.0
Web Terminal - update to 1.3
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
libglib2.0-0 (Ubuntu package) - addressed in versions 2.48.2-0ubuntu4.7, 2.56.4-0ubuntu0.18.04.7, 2.64.6-1~ubuntu20.04.2, 2.66.1-2ubuntu0.1
libgio-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgio-2_0-0-32bit - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgthread-2_0-0-32bit - update to 2.48.2-12.22.1
libgio-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-tools-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-tools - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-debugsource - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgthread-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgthread-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
glib2-lang - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgio-fam - update to 2.48.2-12.22.1
libgio-fam-debuginfo - update to 2.48.2-12.22.1
glib2-devel - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-devel-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
glib2-devel-static - update to 2.48.2-12.22.1
libglib-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgthread-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgobject-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
libgobject-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgobject-2_0-0-32bit - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgobject-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgmodule-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
libgmodule-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgmodule-2_0-0-32bit - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgmodule-2_0-0 - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libglib-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
libglib-2_0-0-debuginfo - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libglib-2_0-0-32bit - addressed in versions 2.48.2-12.22.1, 2.54.3-4.24.1, 2.62.6-3.6.1
libgio-2_0-0-debuginfo-32bit - update to 2.48.2-12.22.1
libgobject-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-4.24.1, 2.62.6-3.6.1
libgmodule-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-4.24.1, 2.62.6-3.6.1
libglib-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-4.24.1, 2.62.6-3.6.1
libgio-2_0-0-32bit-debuginfo - addressed in versions 2.54.3-4.24.1, 2.62.6-3.6.1
glib2 - addressed in versions 2.56.4-8, 2.56.4-10
glib2-tests - addressed in versions 2.56.4-8, 2.56.4-10
glib2-fam - addressed in versions 2.56.4-8, 2.56.4-10
glib2-devel - addressed in versions 2.56.4-8, 2.56.4-10
glib2-help - addressed in versions 2.62.5-4, 2.62.5-6
glib2-devel - addressed in versions 2.62.5-4, 2.62.5-6
glib2-debugsource - addressed in versions 2.62.5-4, 2.62.5-6
glib2-debuginfo - addressed in versions 2.62.5-4, 2.62.5-6
glib2 - addressed in versions 2.62.5-4, 2.62.5-6
mingw-glib2 - addressed in versions 2.66.7-1.fc33, 2.66.7-1.fc34
mingw-glib2 (Red Hat package) - update to 2.66.7-2.el8
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC VxRail Appliance - update to 7.0.240
Xenial Stemcells - addressed in versions 456.150, 621.113
External References
Related Security Bulletins
- Privilege escalation in GNOME GLib
- Multiple vulnerabilities in Cloud Foundry products
- Red Hat Enterprise Linux 7 update for glib2
- Red Hat Enterprise Linux 8 update for glib2
- Red Hat Enterprise Linux 8.1 update for glib2
- Red Hat Enterprise Linux 8.2 update for glib2
- Red Hat Enterprise Linux 7.3 update for glib2
- Red Hat Enterprise Linux 7.4 update for glib2
- Red Hat Enterprise Linux 7.7 update for glib2
- Red Hat Enterprise Linux 7.2 update for glib2
- Red Hat Enterprise Linux 7.6 update for glib2
- CentOS 7 update for glib2
- Multiple vulnerabilities in Openshift Logging
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for glib2
- Multiple vulnerabilities in Red Hat Virtualization
- Red Hat Virtualization Host security update for ovirt
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Windows Container Support for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Gentoo update for GLib
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers
- Amazon Linux AMI update for glib2
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Red Hat Web Terminal
- Red Hat Enterprise Linux 8 update for mingw-glib2
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in IBM Security Verify Access
- Ubuntu update for glib2.0
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Integer overflow in IBM Elastic Storage System
- SUSE update for glib2
- SUSE update for glib2
- SUSE update for glib2
- openEuler 20.03 LTS SP1 update for glib2
- Multiple vulnerabilities in IBM Integrated Analytics System
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Fedora 33 update for mingw-glib2
- Fedora 34 update for mingw-glib2
- openEuler 20.03 LTS update for glib2
- Anolis OS update for glib2 (Anolis OS 8.2)
- Anolis OS update for glib2 (Anolis OS 8.4)