Improper Certificate Validation in Go programming language - CVE-2021-34558

 

Improper Certificate Validation in Go programming language - CVE-2021-34558

Published: August 9, 2021 / Updated: August 25, 2021


Vulnerability identifier: #VU55665
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34558
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper certificate verification in crypto/tls package in Go when processing X.509 certificates. The application does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.


Affected software

Go programming language
Gentoo Linux
Arch Linux
Oracle Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Module for Development Tools
openEuler
golang-github-prometheus-promu (Red Hat package)
containernetworking-plugins (Red Hat package)
golang-github-vbatts-tar-split (Red Hat package)
butane (Red Hat package)
kubevirt (Red Hat package)
go-toolset-1.15 (Red Hat package)
go-toolset-1.15-golang (Red Hat package)
cri-o (Red Hat package)
cri-tools (Red Hat package)
ignition (Red Hat package)
jenkins (Red Hat package)
etcd (Red Hat package)
openshift-kuryr (Red Hat package)
openshift-ansible (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
openstack-ironic (Red Hat package)
ovn2.13 (Red Hat package)
redhat-release-coreos (Red Hat package)
toolbox-tests
toolbox
udica
containernetworking-plugins
rosa (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
delve
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
golang
golang-help
golang-devel
golang-misc
go-toolset
golang-bin
golang-race
golang-tests
golang-docs
golang-src
go1.15-race
go1.15-doc
go1.15
buildah
buildah-debugsource
buildah-debuginfo
buildah-tests
containers-common
go
conmon
container-selinux
podman
python3-criu
criu-libs
criu-devel
criu
crit
podman (Red Hat package)
libslirp-devel
libslirp
python3-podman
podman-gvproxy
podman-catatonit
podman-plugins
podman-remote
podman-tests
podman-docker
mcg (Red Hat package)
grafana (Red Hat package)
grafana
cockpit-podman
ObjectScale
Asset Repository in IBM Cloud Pak for Integration (CP4I)
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Dell PowerProtect Cyber Recovery
Red Hat Developer Tools
App Connect Enterprise Certified Container
IBM Cloud Pak for Multicloud Management Monitoring
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Automation Manager
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Operations Dashboard
Red Hat Advanced Cluster Management for Kubernetes
QRadar Suite
Juniper Secure Analytics (JSA)
Splunk Enterprise
Red Hat OpenShift Jaeger
IBM Cloud Pak System
Red Hat Container Native Virtualization
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
IBM Qradar SIEM
Cloud Pak for Data
IBM Security Verify Access

How to mitigate CVE-2021-34558

Install updates from vendor's website.

Go programming language - update to 1.16.6
golang-github-prometheus-promu (Red Hat package) - update to 0.5.0-4.git642a960.el8
containernetworking-plugins (Red Hat package) - update to 0.8.6-3.rhaos4.6.el7
golang-github-vbatts-tar-split (Red Hat package) - update to 0.11.1-6.el8ost
butane (Red Hat package) - update to 0.12.1-2.rhaos4.8.el8
kubevirt (Red Hat package) - addressed in versions 2.6.8-211.el7, 2.6.8-211.el8, 4.8.5-278.el7, 4.8.5-278.el8
ObjectScale - update to 1.3.0
App Connect Enterprise Certified Container - addressed in versions 1.1.3, 1.5.2
QRadar Suite - update to 1.10.18.0
go-toolset-1.15 (Red Hat package) - update to 1.15.14-1.el7_9
go-toolset-1.15-golang (Red Hat package) - update to 1.15.14-1.el7_9
Red Hat OpenShift Jaeger - update to 1.20.5
cri-o (Red Hat package) - addressed in versions 1.19.3-8.rhaos4.6.git0fa2911.el7, 1.19.3-8.rhaos4.6.git0fa2911.el8, 1.20.4-7.rhaos4.7.git6287500.el7, 1.20.4-7.rhaos4.7.git6287500.el8, 1.21.2-8.rhaos4.8.git8d4264e.el7, 1.21.2-8.rhaos4.8.git8d4264e.el8, 1.21.2-13.rhaos4.8.git52b3f98.el7, 1.21.2-13.rhaos4.8.git52b3f98.el8, 1.21.3-6.rhaos4.8.gite34bf50.el7, 1.21.3-6.rhaos4.8.gite34bf50.el8
cri-tools (Red Hat package) - update to 1.21.0-3.el8
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-4, 4.0.2
OpenShift Virtualization - addressed in versions 2.6.7, 2.6.8, 4.8.1, 4.8.2, 4.8.5, 4.9.0, 4.9.2, 4.10.0
ignition (Red Hat package) - addressed in versions 2.6.0-8.rhaos4.6.git947598e.el8, 2.9.0-4.rhaos4.7.git1d56dc8.el8, 2.9.0-7.rhaos4.8.el8
jenkins (Red Hat package) - update to 2.289.3.1633554819-1.el8
etcd (Red Hat package) - update to 3.3.23-7.el8ost
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 4
Red Hat OpenShift Container Platform - addressed in versions 4.6.42, 4.7.23, 4.8.4, 4.8.9, 4.8.15
openshift-kuryr (Red Hat package) - addressed in versions 4.6.0-202107300032.p0.git.0063daa.el8, 4.7.0-202107291238.p0.git.c7654fb.assembly.stream.el8, 4.8.0-202107291413.p0.git.8a4c2d8.assembly.stream.el8
openshift-ansible (Red Hat package) - addressed in versions 4.6.0-202107292126.p0.git.4ec6967.el7, 4.7.0-202107292046.p0.git.e1b19c2.assembly.stream.el7, 4.8.0-202107292023.p0.git.626f7a3.assembly.stream.el7, 4.8.0-202109241839.p0.git.4bb45f8.assembly.stream.el7
openshift (Red Hat package) - addressed in versions 4.6.0-202107292126.p0.git.4c3480d.el7, 4.6.0-202107292126.p0.git.4c3480d.el8, 4.7.0-202107292242.p0.git.558d959.assembly.stream.el7, 4.7.0-202107292242.p0.git.558d959.assembly.stream.el8, 4.8.0-202107300027.p0.git.38b3ecc.assembly.stream.el7, 4.8.0-202107300027.p0.git.38b3ecc.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.6.0-202107292126.p0.git.2b525e8.el7, 4.6.0-202107292126.p0.git.2b525e8.el8, 4.7.0-202107292242.p0.git.8b4b094.assembly.stream.el7, 4.7.0-202107292242.p0.git.8b4b094.assembly.stream.el8, 4.8.0-202107292313.p0.git.1077b05.assembly.stream.el7, 4.8.0-202107292313.p0.git.1077b05.assembly.stream.el8, 4.8.0-202108120034.p0.git.0d10c3f.assembly.stream.el7, 4.8.0-202108120034.p0.git.0d10c3f.assembly.stream.el8
atomic-openshift-service-idler (Red Hat package) - addressed in versions 4.6.0-202107291238.p0.git.39cfc66.el8, 4.7.0-202107291238.p0.git.39cfc66.assembly.stream.el8, 4.8.0-202107291413.p0.git.39cfc66.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.8.1633555500-1.el8
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Red Hat OpenStack - update to 16.2
openstack-ironic (Red Hat package) - update to 17.0.4-0.20210730151213.5b801be.el8
ovn2.13 (Red Hat package) - update to 20.12.0-140.el8fdp
redhat-release-coreos (Red Hat package) - update to 47.84-1.el8
Asset Repository in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-3, 2021.2.1-1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-4, 2021.3.1
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
containernetworking-plugins - addressed in versions 1.0.0-0.3.rc1.fc33, 1.0.0-0.3.rc1.fc34
rosa (Red Hat package) - update to 1.1.1-51c4a5e.el8
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-2.0.1
delve - update to 1.5.0-2
Migration Toolkit for Containers - update to 1.5.1
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
golang - update to 1.15.7-5
golang-help - update to 1.15.7-5
golang-devel - update to 1.15.7-5
golang-misc - update to 1.15.14-1
go-toolset - update to 1.15.14-1
golang - update to 1.15.14-1
golang-bin - update to 1.15.14-1
golang-race - update to 1.15.14-1
golang-tests - update to 1.15.14-1
golang-docs - update to 1.15.14-1
golang-src - update to 1.15.14-1
golang - addressed in versions 1.15.14-1.el7, 1.15.14-1.fc33, 1.16.6-1.fc34
go1.15-race - update to 1.15.14-1.36.1
go1.15-doc - update to 1.15.14-1.36.1
go1.15 - update to 1.15.14-1.36.1
buildah - addressed in versions 1.21.4-5.fc33, 1.21.4-5.fc34
buildah-debugsource - update to 1.26.1-4
buildah - update to 1.26.1-4
buildah-debuginfo - update to 1.26.1-4
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common - update to 1-81.0.1
go - update to 2
conmon - update to 2.1.10-1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.2
container-selinux - update to 2.229.0-2
podman - addressed in versions 3.2.3-2.fc33, 3.2.3-2.fc34
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
podman (Red Hat package) - update to 4.2.0-3.el9
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.9.0, 4.10.0
python3-podman - update to 4.9.0-1
podman-gvproxy - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
mcg (Red Hat package) - update to 5.9.0-28.61dcf87.5.9.el8
grafana (Red Hat package) - update to 7.5.9-4.el8
grafana - addressed in versions 7.5.9-4.fc34, 7.5.10-1.fc34
IBM Security Verify Access - update to 10.0.9
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
cockpit-podman - update to 84.1-1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins