Improper Verification of Cryptographic Signature in libdnf - CVE-2021-3445
Published: June 30, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient verification of cryptographic signature in libdnf. A remote attacker can create a specially crafted RPM package with altered header information, trick the victim into installing it and compromise the affected system.
Affected software
libdnf (Red Hat package)
dnf-plugins-core (Red Hat package)
dnf (Red Hat package)
libdnf
python3-hawkey
libdnf-devel
python2-libdnf
libdnf-debuginfo
python3-libdnf
libdnf-debugsource
python2-hawkey
rpm-ostree
Cloud Pak for Security (CP4S)
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
How to mitigate CVE-2021-3445
libdnf (Red Hat package) - update to 0.63.0-3.el8
Cloud Pak for Security (CP4S) - update to 1.10.7.0
dnf-plugins-core (Red Hat package) - update to 4.0.21-3.el8
dnf (Red Hat package) - update to 4.7.0-4.el8
libdnf - update to 0.48.0-2
python3-hawkey - update to 0.48.0-2
libdnf-devel - update to 0.48.0-2
python2-libdnf - update to 0.48.0-2
libdnf-debuginfo - update to 0.48.0-2
python3-libdnf - update to 0.48.0-2
libdnf-debugsource - update to 0.48.0-2
python2-hawkey - update to 0.48.0-2
Migration Toolkit for Containers - update to 1.5.4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Red Hat OpenStack - update to 16.2
rpm-ostree - addressed in versions 2021.4-1.fc33, 2021.4-1.fc34
External References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4NL7TNWAHJ6JVRABQUPWHKKCTHUZMNF/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932079
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DPMFGGQ5T6WVFTFX3OKMVTTM5O4EXWZR/
Related Security Bulletins
- Remote code execution in libdnf
- Red Hat Enterprise Linux 8 update for dnf
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- openEuler 20.03 LTS SP1 update for libdnf
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Fedora 33 update for rpm-ostree
- Fedora 34 update for rpm-ostree
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2