Out-of-bounds read in rpm - CVE-2021-20266

 

Out-of-bounds read in rpm - CVE-2021-20266

Published: June 30, 2021


Vulnerability identifier: #VU54478
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20266
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the hdrblobInit() function in lib/header.c. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.


Affected software

rpm
Gentoo Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Proxy
SUSE MicroOS
IBM AIX
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
Cloud Pak for Security (CP4S)
IBM VIOS
rpm (Red Hat package)
rpm-debuginfo
rpm
rpm-debugsource
rpm-devel
python3-rpm
python3-rpm-debuginfo
python3-rpm-debugsource
rpm-build
rpm-build-debuginfo
rpm-python
rpm-python-debuginfo
rpm-python-debugsource
rpm-32bit
rpm-debuginfo-32bit
python-rpm-debugsource
python2-rpm
python2-rpm-debuginfo
rpm-32bit-debuginfo
rpm-ndb-debugsource
rpm-ndb-debuginfo
rpm-ndb
rpm-cron
rpm-build-libs
rpm-libs
rpm-plugin-ima
rpm-plugin-prioreset
rpm-plugin-selinux
rpm-plugin-syslog
rpm-plugin-systemd-inhibit
rpm-sign
rpm-apidocs
rpm-help
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Dell EMC NetWorker vProxy
RecoverPoint for VMs

How to mitigate CVE-2021-20266

Install updates from vendor's website.

rpm - update to 4.16.1.3
Cloud Pak for Security (CP4S) - update to 1.10.7.0
rpm (Red Hat package) - update to 4.14.3-19.el8
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell EMC NetWorker vProxy - update to 4.3.0-40
rpm-debuginfo - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.2, 4.14.3-37.2
rpm - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.2, 4.14.3-37.2
rpm-debugsource - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.2, 4.14.3-37.2
rpm-devel - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.2, 4.14.3-37.2
python3-rpm - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.1, 4.14.3-37.2
python3-rpm-debuginfo - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.1, 4.14.3-37.2
python3-rpm-debugsource - update to 4.11.2-16.26.1
rpm-build - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.2, 4.14.3-37.2
rpm-build-debuginfo - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.2, 4.14.3-37.2
rpm-python - update to 4.11.2-16.26.1
rpm-python-debuginfo - update to 4.11.2-16.26.1
rpm-python-debugsource - update to 4.11.2-16.26.1
rpm-32bit - addressed in versions 4.11.2-16.26.1, 4.14.1-22.4.2, 4.14.3-37.2
rpm-debuginfo-32bit - update to 4.11.2-16.26.1
python-rpm-debugsource - addressed in versions 4.14.1-22.4.1, 4.14.3-37.2
python2-rpm - addressed in versions 4.14.1-22.4.1, 4.14.3-37.2
python2-rpm-debuginfo - addressed in versions 4.14.1-22.4.1, 4.14.3-37.2
rpm-32bit-debuginfo - addressed in versions 4.14.1-22.4.2, 4.14.3-37.2
rpm-ndb-debugsource - addressed in versions 4.14.1-22.4.2, 4.14.3-37.2
rpm-ndb-debuginfo - addressed in versions 4.14.1-22.4.2, 4.14.3-37.2
rpm-ndb - addressed in versions 4.14.1-22.4.2, 4.14.3-37.2
rpm-cron - update to 4.14.3-19.0.2
python3-rpm - update to 4.14.3-19.0.2
rpm - update to 4.14.3-19.0.2
rpm-build - update to 4.14.3-19.0.2
rpm-build-libs - update to 4.14.3-19.0.2
rpm-devel - update to 4.14.3-19.0.2
rpm-libs - update to 4.14.3-19.0.2
rpm-plugin-ima - update to 4.14.3-19.0.2
rpm-plugin-prioreset - update to 4.14.3-19.0.2
rpm-plugin-selinux - update to 4.14.3-19.0.2
rpm-plugin-syslog - update to 4.14.3-19.0.2
rpm-plugin-systemd-inhibit - update to 4.14.3-19.0.2
rpm-sign - update to 4.14.3-19.0.2
rpm-apidocs - update to 4.14.3-19.0.2
rpm - addressed in versions 4.15.1.1-1.fc32.1, 4.16.1.3-1.fc33, 4.16.1.3-1.fc34
rpm-devel - update to 4.15.1-24
rpm - update to 4.15.1-24
rpm-build - update to 4.15.1-24
rpm-libs - update to 4.15.1-24
python3-rpm - update to 4.15.1-24
rpm-help - update to 4.15.1-24
rpm-debuginfo - update to 4.15.1-24
rpm-debugsource - update to 4.15.1-24
python2-rpm - update to 4.15.1-24
RecoverPoint for VMs - update to 6.0.SP1.P1

External References

Related Security Bulletins