Race condition in crossbeam-deque - CVE-2021-32810
Published: August 5, 2021 / Updated: October 5, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a race condition in the "Stealer::steal", "Stealer::steal_batch" and "Stealer::steal_batch_and_pop" functions. A remote attacker can exploit the race and gain unauthorized access to sensitive information and execute arbitrary code on the system.
Affected software
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
CentOS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Module for Desktop Applications
Ubuntu
Fedora
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rust-unicode-linebreak
rust-argh
rust-argh_derive
rust-argh_shared
rust-weezl
rust-unicode-truncate
rust-filetreelist
rust-git-version-macro
rust-git-version
rust-bugreport
rust-rav1e
rust-askalono-cli
rust-shadow-rs
rust-gettext-rs
rust-fancy-regex
rust-crosstermion
rust-sd
rust-pulldown-cmark
rust-skim
rust-diskonaut
zola
rust-textwrap
rust-tui
rust-tui-react
rust-gitui
rust-asyncgit
rust-gettext-sys
rust-starship
rust-fedora-update-feedback
rust-urlencoding
newsflash
rust-heatseeker
rust-jql
rust-dua-cli
newsboat
rust-versions
rust-tokei
thunderbird (Red Hat package)
MozillaFirefox
MozillaFirefox-debuginfo
MozillaFirefox-debugsource
MozillaFirefox-devel
MozillaFirefox-translations-common
MozillaFirefox-translations-other
firefox (Red Hat package)
thunderbird (Ubuntu package)
MozillaThunderbird
MozillaThunderbird-translations-other
MozillaThunderbird-translations-common
MozillaThunderbird-debugsource
MozillaThunderbird-debuginfo
MozillaFirefox-branding-SLE
thunderbird
firefox
MozillaFirefox-branding-SLED
firefox (Ubuntu package)
Mozilla Firefox
Firefox ESR
Mozilla Thunderbird
How to mitigate CVE-2021-32810
Mozilla Firefox - update to 93.0
Firefox ESR - update to 91.2.0
Mozilla Thunderbird - update to 91.2.0
rust-unicode-linebreak - update to 0.1.1-2.fc34
rust-argh - update to 0.1.5-2.fc34
rust-argh_derive - update to 0.1.5-2.fc34
rust-argh_shared - update to 0.1.5-2.fc34
rust-weezl - update to 0.1.5-3.fc34
rust-unicode-truncate - update to 0.2.0-2.fc34
rust-filetreelist - update to 0.2.0-3.fc34
rust-git-version-macro - update to 0.3.4-1.fc34
rust-git-version - update to 0.3.4-1.fc34
rust-bugreport - update to 0.4.0-2.fc34
rust-rav1e - update to 0.4.1-4.fc34
rust-askalono-cli - update to 0.4.3-5.fc34
rust-shadow-rs - update to 0.6.3-1.fc34
rust-gettext-rs - update to 0.7.0-1.fc34
rust-fancy-regex - update to 0.7.0-1.fc34
rust-crosstermion - update to 0.7.0-2.fc34
rust-sd - update to 0.7.6-4.fc34
rust-pulldown-cmark - update to 0.8.0-4.fc34
rust-skim - update to 0.9.4-4.fc34
rust-diskonaut - update to 0.11.0-5.fc34
zola - update to 0.12.2-6.fc34
rust-textwrap - update to 0.14.2-3.fc34
rust-tui - update to 0.15.0-2.fc34
rust-tui-react - update to 0.15.0-2.fc34
rust-gitui - update to 0.16.2-2.fc34
rust-asyncgit - update to 0.16.3-3.fc34
rust-gettext-sys - update to 0.21.2-1.fc34
rust-starship - update to 0.56.0-2.fc34
rust-fedora-update-feedback - update to 1.0.3-1.fc34
rust-urlencoding - update to 1.3.3-1.fc34
newsflash - update to 1.4.1-2.fc34
rust-heatseeker - update to 1.7.1-6.fc34
rust-jql - update to 2.9.4-2.fc34
rust-dua-cli - update to 2.11.1-3.fc34
newsboat - update to 2.24-1.fc34
rust-versions - update to 3.0.2-1.fc34
rust-tokei - update to 12.0.4-7.fc34
thunderbird (Red Hat package) - addressed in versions 91.2.0-1.el7_9, 91.2.0-1.el8_1, 91.2.0-1.el8_2, 91.2.0-1.el8_4
MozillaFirefox - addressed in versions 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.2.0-112.74.1
MozillaFirefox-debuginfo - addressed in versions 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.2.0-112.74.1
MozillaFirefox-debugsource - addressed in versions 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-112.74.1
MozillaFirefox-devel - addressed in versions 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-112.74.1
MozillaFirefox-translations-common - addressed in versions 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1, 91.2.0-112.74.1
MozillaFirefox-translations-other - addressed in versions 91.2.0-3.155.2, 91.2.0-8.54.1, 91.2.0-78.143.1
firefox (Red Hat package) - addressed in versions 91.2.0-4.el7_9, 91.2.0-4.el8_1, 91.2.0-4.el8_2, 91.2.0-4.el8_4
thunderbird (Ubuntu package) - update to 1:91.2.1+build1-0ubuntu0.21.10.1
MozillaThunderbird - update to 91.4.0-8.45.2
MozillaThunderbird-translations-other - update to 91.4.0-8.45.2
MozillaThunderbird-translations-common - update to 91.4.0-8.45.2
MozillaThunderbird-debugsource - update to 91.4.0-8.45.2
MozillaThunderbird-debuginfo - update to 91.4.0-8.45.2
MozillaFirefox-branding-SLE - addressed in versions 91-4.19.1, 91-9.5.1
thunderbird - update to 91.6.0-1.0.1
firefox - update to 91.6.0-1.0.1
MozillaFirefox-branding-SLED - update to 91-21.18.1
firefox (Ubuntu package) - addressed in versions 93.0+build1-0ubuntu0.18.04.1, 93.0+build1-0ubuntu0.20.04.1, 93.0+build1-0ubuntu0.21.04.1
External References
Related Security Bulletins
- Remote code execution in crossbeam-deque
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- Red Hat Enterprise Linux 8 update for firefox
- Red Hat Enterprise Linux 8.2 update for firefox
- Red Hat Enterprise Linux 8.1 update for firefox
- Red Hat Enterprise Linux 7 update for firefox
- Red Hat Enterprise Linux 8 update for thunderbird
- Red Hat Enterprise Linux 8.2 update for thunderbird
- Red Hat Enterprise Linux 8.1 update for thunderbird
- Red Hat Enterprise Linux 7 update for thunderbird
- CentOS 7 update for thunderbird
- CentOS 7 update for firefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox, rust-cbindgen
- Ubuntu update for firefox
- Ubuntu update for thunderbird
- SUSE update for MozillaThunderbird
- Fedora 34 update for rust-shadow-rs, rust-starship, rust-urlencoding, rust-versions
- Fedora 34 update for rust-heatseeker
- Fedora 34 update for rust-askalono-cli
- Fedora 34 update for rust-diskonaut
- Fedora 34 update for rust-dua-cli
- Fedora 34 update for rust-jql
- Fedora 34 update for rust-pulldown-cmark
- Fedora 34 update for rust-rav1e
- Fedora 34 update for rust-sd
- Fedora 34 update for rust-skim
- Fedora 34 update for rust-tokei
- Fedora 34 update for rust-weezl
- Fedora 34 update for zola
- Fedora 34 update for rust-argh, rust-argh_derive, rust-argh_shared, rust-asyncgit, rust-bugreport, rust-crosstermion, rust-fancy-regex, rust-fedora-update-feedback, rust-filetreelist, rust-git-version, rust-git-version-macro, rust-gitui, rust-textwrap, ru
- Fedora 34 update for newsboat, newsflash, rust-gettext-rs, rust-gettext-sys
- Anolis OS update for thunderbird (Anolis OS 8.5)
- Anolis OS update for firefox