Use-after-free in cURL - CVE-2021-22901
Published: May 26, 2021
Vulnerability details
The vulnerability allows a remote attacker to crash the application or compromise the vulnerable system.
The vulnerability exists due to a use-after-free error when processing creation of new TLS sessions or during client certificate negotiation. A remote attacker can force the application to connect to a malicious server, trigger a use-after-free error and crash the application.
Remote code execution is also possible if the application can be forced to initiate multiple transfers with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection in order to inject a crafted memory content into the correct place in memory.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system but requires that libcurl is using OpenSSL.
Affected software
Gentoo Linux
Arch Linux
Slackware Linux
Fedora
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM MaaS360 Ceriticate Integration Module
IBM MaaS360 Base Module
jbcs-httpd24 (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
curl
EasyApache
Oracle HTTP Server
IBM MaaS360 Cloud Extender Agent
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
MySQL Server
Oracle Essbase
Splunk Universal Forwarder
IBM Aspera High-Speed Transfer Server
Splunk Enterprise
SINEC INS
JBoss Core Services
IBM MaaS360 VPN Module
IBM Aspera High-Speed Transfer Endpoint
IBM Aspera Desktop Client
How to mitigate CVE-2021-22901
jbcs-httpd24 (Red Hat package) - addressed in versions 1-18.el8jbcs, 1-18.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-82.el8jbcs, 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-105.el8jbcs, 1.6.3-105.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-17.el8jbcs, 1.15.7-17.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-36.el8jbcs, 2.0.8-36.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-74.el8jbcs, 2.4.37-74.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-63.GA.el8jbcs, 2.9.2-63.GA.jbcs.el7
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.11-55.el8jbcs, 2.11-55.jbcs.el7
EasyApache - update to 4 2021-6-2
MySQL Server - addressed in versions 5.7.35, 8.0.26
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.77.0-2.el8jbcs, 7.77.0-2.jbcs.el7
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Oracle Essbase - addressed in versions 11.1.2.4.047, 21.3
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.el8jbcs
SINEC INS - update to 1.0.1.1
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.el8jbcs
JBoss Core Services - update to 2.4.37 SP8
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Base Module - update to 2.105.300.005
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Aspera High-Speed Transfer Endpoint - update to 4.2
IBM Aspera High-Speed Transfer Server - update to 4.2
IBM Aspera Desktop Client - update to 4.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
curl - update to 7.76.1-3.fc34
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Gentoo update for cURL
- Slackware Linux update for curl
- Arch Linux update for curl
- Arch Linux update for lib32-curl
- Arch Linux update for libcurl-compat
- Arch Linux update for lib32-libcurl-compat
- cPanel update for EasyApache
- Red Hat update for JBoss Core Services Pack Apache Server
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in Oracle Essbase
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in IBM Aspera High-Speed Transfer Server, Endpoint, and Desktop Client
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender and Modules
- Splunk Universal Forwarder update for third-party packages
- Multiple vulnerabilities in Dell Data Protection Central
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Fedora 34 update for curl