Input validation error in GNU C Library (glibc) - CVE-2016-10228
Published: June 23, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
Affected software
SIMATIC S7-1500 TM MFP - BIOS
Gentoo Linux
SUSE MicroOS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
Ubuntu
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
Service Telemetry Framework
cflinuxfs3
Tanzu Greenplum for Kubernetes
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
VMware Tanzu Operations Manager
Cloud Pak for Security (CP4S)
RecoverPoint for Virtual Machines
Red Hat OpenShift Jaeger
IBM Security Verify Access
libc6 (Ubuntu package)
glibc
glibc-debuginfo
glibc-info
glibc-debugsource
glibc-devel-static
glibc-i18ndata
glibc-html
glibc-profile-32bit
glibc-locale-debuginfo-32bit
glibc-locale-32bit
glibc-devel-32bit
glibc-devel
glibc-devel-debuginfo
glibc-locale
glibc-locale-debuginfo
glibc-profile
nscd
nscd-debuginfo
glibc-32bit
glibc-debuginfo-32bit
glibc-devel-debuginfo-32bit
glibc-extra-debuginfo
glibc-locale-base
glibc-locale-base-debuginfo
glibc-utils
glibc-utils-debuginfo
glibc-utils-src-debugsource
glibc-32bit-debuginfo
glibc-devel-32bit-debuginfo
glibc-extra
glibc-locale-base-32bit
glibc-locale-base-32bit-debuginfo
glibc (Red Hat package)
sys-libs/glibc
Web Terminal
Dell EMC VxRail Appliance
How to mitigate CVE-2016-10228
cflinuxfs3 - update to 0.275.0
Red Hat OpenShift Serverless - update to 1.16.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
libc6 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.27-3ubuntu1.5, 2.31-0ubuntu9.7, 2.34-0ubuntu3.2
Web Terminal - update to 1.3
Tanzu Greenplum for Kubernetes - update to 2.0.0
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
VMware Tanzu Operations Manager - update to 2.10.52
glibc - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-debuginfo - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-info - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-debugsource - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-devel-static - addressed in versions 2.22-114.12.1, 2.26-13.62.1
glibc-i18ndata - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-html - addressed in versions 2.22-114.12.1, 2.22-126.1
glibc-profile-32bit - addressed in versions 2.22-114.12.1, 2.22-126.1
glibc-locale-debuginfo-32bit - addressed in versions 2.22-114.12.1, 2.22-126.1
glibc-locale-32bit - addressed in versions 2.22-114.12.1, 2.22-126.1
glibc-devel-32bit - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-devel - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-devel-debuginfo - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-locale - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-locale-debuginfo - addressed in versions 2.22-114.12.1, 2.22-126.1
glibc-profile - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
nscd - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
nscd-debuginfo - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-32bit - addressed in versions 2.22-114.12.1, 2.22-126.1, 2.26-13.62.1
glibc-debuginfo-32bit - addressed in versions 2.22-114.12.1, 2.22-126.1
glibc-devel-debuginfo-32bit - addressed in versions 2.22-114.12.1, 2.22-126.1
glibc-extra-debuginfo - update to 2.26-13.62.1
glibc-locale-base - update to 2.26-13.62.1
glibc-locale-base-debuginfo - update to 2.26-13.62.1
glibc-utils - update to 2.26-13.62.1
glibc-utils-debuginfo - update to 2.26-13.62.1
glibc-utils-src-debugsource - update to 2.26-13.62.1
glibc-32bit-debuginfo - update to 2.26-13.62.1
glibc-devel-32bit-debuginfo - update to 2.26-13.62.1
glibc-extra - update to 2.26-13.62.1
glibc-locale-base-32bit - update to 2.26-13.62.1
glibc-locale-base-32bit-debuginfo - update to 2.26-13.62.1
glibc (Red Hat package) - update to 2.28-151.el8
glibc - update to 2.31-5.fc32
sys-libs/glibc - update to 2.32-r5
Dell EMC VxRail Appliance - update to 4.7.533
External References
- http://openwall.com/lists/oss-security/2017/03/01/10
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
- https://security.gentoo.org/glsa/202101-20
- https://sourceware.org/bugzilla/show_bug.cgi?id=19519
- https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21
- https://sourceware.org/bugzilla/show_bug.cgi?id=26224
Related Security Bulletins
- Denial of service in GNU C Library
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Windows Container Support for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in Red Hat Web Terminal
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Cloud Foundry cflinuxfs3
- SUSE update for glibc
- SUSE update for glibc
- Ubuntu update for glibc
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Multiple vulnerabilities in IBM Cloud Pak for Security
- SUSE update for glibc
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Ubuntu update for glibc
- Red Hat Enterprise Linux 8 update for glibc
- Gentoo update for glibc
- VMware Tanzu products update for GNU C Library
- Multiple vulnerabilities in Siemens SIMATIC S7-1500 TM MFP - BIOS
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Fedora 32 update for glibc
- Dell RecoverPoint for Virtual Machines update for third-party components