Double Free in GNU C Library (glibc) - CVE-2021-27645
Published: July 6, 2021
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the nameserver caching daemon (nscd) in the GNU C Library when processing a request for netgroup lookup. A local user can initiate a specially crafted request, trigger a double free error and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
SIMATIC S7-1500 TM MFP - BIOS
cflinuxfs3
Cloud Pak for Security (CP4S)
RecoverPoint for Virtual Machines
Red Hat OpenShift Serverless
libc6 (Ubuntu package)
glibc (Red Hat package)
glibc
How to mitigate CVE-2021-27645
Cloud Pak for Security (CP4S) - update to 1.10.7.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
libc6 (Ubuntu package) - addressed in versions 2.27-3ubuntu1.5, 2.31-0ubuntu9.7, 2.34-0ubuntu3.2
glibc (Red Hat package) - update to 2.28-164.el8
glibc - addressed in versions 2.32-6.fc33, 2.33-5.fc34, 2.33.9000-18.fc35
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Red Hat OpenStack - update to 16.2
External References
- https://sourceware.org/bugzilla/show_bug.cgi?id=27462
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/
Related Security Bulletins
- Denial of service in GNU C Library
- Gentoo update for glibc
- Multiple vulnerabilities in Cloud Foundry cflinuxfs3
- Ubuntu update for glibc
- Double free in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for glibc
- Multiple vulnerabilities in Siemens SIMATIC S7-1500 TM MFP - BIOS
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Fedora 34 update for glibc
- Fedora 33 update for glibc
- Fedora 35 update for glibc
- Dell RecoverPoint for Virtual Machines update for third-party components
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2