Double Free in GNU C Library (glibc) - CVE-2021-27645

 

Double Free in GNU C Library (glibc) - CVE-2021-27645

Published: July 6, 2021


Vulnerability identifier: #VU54559
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27645
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the nameserver caching daemon (nscd) in the GNU C Library when processing a request for netgroup lookup. A local user can initiate a specially crafted request, trigger a double free error and perform a denial of service (DoS) attack.


Affected software

GNU C Library (glibc)
Gentoo Linux
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
SIMATIC S7-1500 TM MFP - BIOS
cflinuxfs3
Cloud Pak for Security (CP4S)
RecoverPoint for Virtual Machines
Red Hat OpenShift Serverless
libc6 (Ubuntu package)
glibc (Red Hat package)
glibc

How to mitigate CVE-2021-27645

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

cflinuxfs3 - update to 0.275.0
Cloud Pak for Security (CP4S) - update to 1.10.7.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
libc6 (Ubuntu package) - addressed in versions 2.27-3ubuntu1.5, 2.31-0ubuntu9.7, 2.34-0ubuntu3.2
glibc (Red Hat package) - update to 2.28-164.el8
glibc - addressed in versions 2.32-6.fc33, 2.33-5.fc34, 2.33.9000-18.fc35
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins