Resource exhaustion in Go programming language - CVE-2021-33196
Published: July 4, 2021 / Updated: June 2, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing archives. A remote attacker can pass a specially crafted .zip file to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Arch Linux
Amazon Linux AMI
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Manager Server
SUSE Enterprise Storage
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
openEuler
toolbox (Red Hat package)
openshift-serverless-clients (Red Hat package)
coreos-installer (Red Hat package)
butane (Red Hat package)
console-login-helper-messages (Red Hat package)
python-eventlet (Red Hat package)
python-hardware (Red Hat package)
ignition (Red Hat package)
runc (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
python-sushy-oem-idrac (Red Hat package)
kata-containers (Red Hat package)
python-ironic-prometheus-exporter (Red Hat package)
haproxy (Red Hat package)
openvswitch2.15 (Red Hat package)
jenkins (Red Hat package)
python-sushy (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
python-ironic-lib (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
rust-afterburn (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openstack-ironic-inspector (Red Hat package)
ironic-images (Red Hat package)
python-wcwidth (Red Hat package)
rust-bootupd (Red Hat package)
python-scciclient (Red Hat package)
python-cmd2 (Red Hat package)
delve
python-pyperclip (Red Hat package)
python-pycdlib (Red Hat package)
golang
golang-help
golang-devel
go-toolset-1.15-golang (Red Hat package)
go-toolset-1.15 (Red Hat package)
go1.15-race
go1.15-doc
go1.15
golang-docs
golang-race
golang-tests
golang-src
golang-bin
golang-misc
go-toolset
go1.16-race
go1.16-doc
go1.16
go
python-osc-lib (Red Hat package)
openvswitch2.16 (Red Hat package)
python-cliff (Red Hat package)
python-ironicclient (Red Hat package)
openshift-ansible (Red Hat package)
python-dracclient (Red Hat package)
openstack-ironic-python-agent (Red Hat package)
openstack-ironic (Red Hat package)
ovn21.09 (Red Hat package)
redhat-release-coreos (Red Hat package)
App Connect Enterprise Certified Container
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Multicloud Management Monitoring
IBM Robotic Process Automation
Operations Dashboard
Netcool Operations Insight
Red Hat Advanced Cluster Security for Kubernetes
Red Hat Developer Tools
ObjectScale
Astronomer with IBM
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Asset Repository in IBM Cloud Pak for Integration (CP4I)
Dell PowerProtect Cyber Recovery
Red Hat OpenShift Serverless
QRadar Suite
Splunk Enterprise
Red Hat OpenShift Jaeger
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
OpenShift Serverless Client
SCALANCE LPE9403
How to mitigate CVE-2021-33196
toolbox (Red Hat package) - update to 0.0.8-3.rhaos4.9.el8
openshift-serverless-clients (Red Hat package) - addressed in versions 0.22.0-3.el8, 0.26.0-2.el8
coreos-installer (Red Hat package) - update to 0.10.0-2.rhaos4.9.el8
butane (Red Hat package) - update to 0.13.1-1.rhaos4.9.el8
console-login-helper-messages (Red Hat package) - update to 0.20.3-1.rhaos4.9.el8
python-eventlet (Red Hat package) - update to 0.30.2-1.el8
python-hardware (Red Hat package) - update to 0.28.0-0.20210719162211.96c9863.el8
ignition (Red Hat package) - addressed in versions 2.9.0-7.rhaos4.8.el8, 2.12.0-1.rhaos4.9.el8
App Connect Enterprise Certified Container - addressed in versions 1.1.3, 1.5.2
ObjectScale - update to 1.3.0
Astronomer with IBM - update to 1.0.1
Red Hat OpenShift Serverless - addressed in versions 1.16.0, 1.20.0
runc (Red Hat package) - update to 1.0.1-2.rhaos4.9.git4144b63.el8
QRadar Suite - update to 1.10.17.0
cri-tools (Red Hat package) - update to 1.22.0-1.el8
cri-o (Red Hat package) - addressed in versions 1.21.2-8.rhaos4.8.git8d4264e.el7, 1.21.2-8.rhaos4.8.git8d4264e.el8, 1.22.0-73.rhaos4.9.gitbdf286c.el8
Red Hat OpenShift Jaeger - update to 1.20.5
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-4, 4.0.2
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
python-sushy-oem-idrac (Red Hat package) - update to 2.0.1-0.20210326153413.83b7eb0.el8
kata-containers (Red Hat package) - update to 2.1.0-6.el8
python-ironic-prometheus-exporter (Red Hat package) - update to 2.3.0-0.20210611093526.3c9b517.el8
haproxy (Red Hat package) - update to 2.2.15-1.el8
openvswitch2.15 (Red Hat package) - update to 2.15.0-28.el8fdp
jenkins (Red Hat package) - update to 2.289.3.1630554997-1.el8
python-sushy (Red Hat package) - update to 3.11.0-0.20210802160404.b93dcba.el8
openshift (Red Hat package) - addressed in versions 4.8.0-202107300027.p0.git.38b3ecc.assembly.stream.el7, 4.8.0-202107300027.p0.git.38b3ecc.assembly.stream.el8, 4.9.0-202110080828.p0.git.894a78b.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.8.0-202107292313.p0.git.1077b05.assembly.stream.el7, 4.8.0-202107292313.p0.git.1077b05.assembly.stream.el8, 4.9.0-202109101042.p0.git.96e95ce.assembly.stream.el8
openshift-kuryr (Red Hat package) - addressed in versions 4.8.0-202107291413.p0.git.8a4c2d8.assembly.stream.el8, 4.9.0-202109101042.p0.git.e66f211.assembly.stream.el8
python-ironic-lib (Red Hat package) - update to 4.7.2-0.20210707162243.d33cf3e.el8
atomic-openshift-service-idler (Red Hat package) - addressed in versions 4.8.0-202107291413.p0.git.39cfc66.assembly.stream.el8, 4.9.0-202109101042.p0.git.39cfc66.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.9.1630555871-1.el8
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat OpenShift Container Platform - addressed in versions 4.8.4, 4.9.0, 4.9.23
rust-afterburn (Red Hat package) - update to 5.1.0-1.rhaos4.9.el8
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
openstack-ironic-inspector (Red Hat package) - update to 10.7.1-0.20210722154052.edf655c.el8
IBM Robotic Process Automation - update to 21.0.3.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-4, 2021.3.1
Asset Repository in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-3, 2021.2.1-1
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
ironic-images (Red Hat package) - update to 2021.2-20210827.1.el8
python-wcwidth (Red Hat package) - update to 0.1.7-14.el8ost
rust-bootupd (Red Hat package) - update to 0.2.5-3.rhaos4.9.el8
python-scciclient (Red Hat package) - update to 0.9.1-0.20210720102209.34ccd96.el8
python-cmd2 (Red Hat package) - update to 1.4.0-1.1.el8
delve - addressed in versions 1.5.0-2, 1.7.2-1
Migration Toolkit for Containers - addressed in versions 1.5.1, 1.6.5
python-pyperclip (Red Hat package) - update to 1.6.4-6.el8ost
Netcool Operations Insight - update to 1.6.6
python-pycdlib (Red Hat package) - update to 1.11.0-3.el8
golang - addressed in versions 1.15.7-5, 1.15.7-8
golang-help - addressed in versions 1.15.7-5, 1.15.7-8
golang-devel - addressed in versions 1.15.7-5, 1.15.7-8
go-toolset-1.15-golang (Red Hat package) - update to 1.15.13-1.el7_9
go-toolset-1.15 (Red Hat package) - update to 1.15.13-1.el7_9
go1.15-race - update to 1.15.13-1.33.1
go1.15-doc - update to 1.15.13-1.33.1
go1.15 - update to 1.15.13-1.33.1
golang-docs - addressed in versions 1.15.14-1, 1.17.7-1
golang-race - addressed in versions 1.15.14-1, 1.17.7-1
golang-tests - addressed in versions 1.15.14-1, 1.17.7-1
golang-src - addressed in versions 1.15.14-1, 1.17.7-1
golang-bin - addressed in versions 1.15.14-1, 1.17.7-1
golang-misc - addressed in versions 1.15.14-1, 1.17.7-1
golang - addressed in versions 1.15.14-1, 1.17.7-1
go-toolset - addressed in versions 1.15.14-1, 1.17.7-1
go1.16-race - update to 1.16.5-1.17.1
go1.16-doc - update to 1.16.5-1.17.1
go1.16 - update to 1.16.5-1.17.1
golang - update to 1.16.13-2.el7
golang - update to 1.19.3-2
OpenShift Serverless Client - update to 1.20.0
SCALANCE LPE9403 - update to 2.0
go - update to 2
python-osc-lib (Red Hat package) - update to 2.3.1-0.20210318171847.2b7a679.el8
openvswitch2.16 (Red Hat package) - update to 2.16.0-15.el8fdp
python-cliff (Red Hat package) - update to 3.7.0-0.20210318182629.117a100.el8
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
python-ironicclient (Red Hat package) - update to 4.7.1-0.20210611202214.3d146fb.el8
openshift-ansible (Red Hat package) - update to 4.8.0-202107292023.p0.git.626f7a3.assembly.stream.el7
python-dracclient (Red Hat package) - update to 5.1.1-0.20210318155434.98c7ea3.el8
openstack-ironic-python-agent (Red Hat package) - update to 8.1.1-0.20210722155129.7f3de67.el8
openstack-ironic (Red Hat package) - update to 18.1.1-0.20210812092216.4aec741.el8
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
ovn21.09 (Red Hat package) - update to 21.09.0-20.el8fdp
redhat-release-coreos (Red Hat package) - update to 49.84-2.el8
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=1965503
- https://github.com/golang/go/issues/46242
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33912
- https://go-review.googlesource.com/c/go/+/322949/
- https://go-review.googlesource.com/c/go/+/322909/
- https://go-review.googlesource.com/c/go/+/318909/
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- Red Hat Developer Tools update for go-toolset-1.15 and go-toolset-1.15-golang
- Multiple vulnerabilities in OpenShift Serverless Client
- Multiple vulnerabilities in OpenShift Serverless
- Red Hat Enterprise Linux 8.4 update for the go-toolset:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers
- Multiple vulnerabilities in IBM Watson Discovery for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.9
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in Siemens SCALANCE LPE9403
- SUSE update for go1.16
- SUSE update for go1.15
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Gentoo update for Go
- Multiple vulnerabilities in IBM Cloud Pak for Integration
- Multiple vulnerabilities in IBM Operations Dashboard
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Denial of service in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Netcool Operations Insight
- Arch Linux update for go
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar Suite software
- openEuler update for golang
- openEuler update for golang
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in OpenShift Serverless Client 1.20
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Multiple vulnerabilities in Migration Toolkit for Containers 1.6
- Fedora EPEL 7 update for golang
- Anolis OS update for go-toolset:an8 module
- Anolis OS update for go-toolset:an8 module
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Astronomer with IBM
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data