Race condition in Go programming language - CVE-2021-36221

 

Race condition in Go programming language - CVE-2021-36221

Published: August 10, 2021


Vulnerability identifier: #VU55668
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36221
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a race condition in net/http/httputil ReverseProxy when handling ErrAbortHandler events. A remote attacker can trigger a race condition and crash the ReverseProxy.


Affected software

Go programming language
Amazon Linux AMI
Gentoo Linux
Oracle Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
openEuler
openshift-serverless-clients (Red Hat package)
golang-github-prometheus-promu (Red Hat package)
butane (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
ignition (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
jenkins-2-plugins (Red Hat package)
golang-devel
golang-help
golang
go1.15-race
go1.15-doc
go1.15
go1.16-race
go1.16-doc
go1.16
mcg (Red Hat package)
ovn21.12 (Red Hat package)
Routing Release
Red Hat OpenShift Serverless
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
ObjectScale
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Asset Repository in IBM Cloud Pak for Integration (CP4I)
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Multicloud Management Monitoring
IBM Robotic Process Automation
Operations Dashboard
Netcool Operations Insight
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
CF Deployment
SCALANCE LPE9403

How to mitigate CVE-2021-36221

Install updates from vendor's website.

Go programming language - addressed in versions 1.15.15, 1.16.7
openshift-serverless-clients (Red Hat package) - update to 0.25.1-1.el8
golang-github-prometheus-promu (Red Hat package) - update to 0.5.0-5.git642a960.el8
butane (Red Hat package) - update to 0.13.1-2.rhaos4.9.el8
Routing Release - update to 0.221.0
Red Hat OpenShift Serverless - update to 1.19.0
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
cri-tools (Red Hat package) - update to 1.22.0-2.el8
cri-o (Red Hat package) - addressed in versions 1.22.1-17.rhaos4.9.git3029b1d.2.el8, 1.22.1-17.rhaos4.9.git3029b1d.el7
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-4, 4.0.2
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
ignition (Red Hat package) - update to 2.12.0-3.rhaos4.9.el8
openshift-ansible (Red Hat package) - update to 4.9.0-202202111950.p0.g4d833d3.assembly.stream.el7
openshift-clients (Red Hat package) - addressed in versions 4.9.0-202202140924.p0.g340e212.assembly.stream.el7, 4.9.0-202202140924.p0.g340e212.assembly.stream.el8
OpenShift Virtualization - addressed in versions 4.9.4, 4.10.0, 4.10.1
Red Hat OpenShift Container Platform - update to 4.9.22
openshift (Red Hat package) - addressed in versions 4.9.0-202202111950.p0.gb93fd35.assembly.stream.el7, 4.9.0-202202111950.p0.gb93fd35.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.9.1644822177-1.el8
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
CF Deployment - update to 16.22.0
IBM Robotic Process Automation - update to 21.0.3.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-4, 2021.3.1
Asset Repository in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-3, 2021.2.1-1
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
Migration Toolkit for Containers - update to 1.5.4
Netcool Operations Insight - update to 1.6.6
golang-devel - update to 1.15.7-5
golang-help - update to 1.15.7-5
golang - update to 1.15.7-5
golang - addressed in versions 1.15.15-1.fc33, 1.16.8-1.fc34, 1.16.8-2.fc35, 1.16.13-2.el7
go1.15-race - update to 1.15.15-1.39.1
go1.15-doc - update to 1.15.15-1.39.1
go1.15 - update to 1.15.15-1.39.1
go1.16-race - update to 1.16.7-1.23.1
go1.16-doc - update to 1.16.7-1.23.1
go1.16 - update to 1.16.7-1.23.1
SCALANCE LPE9403 - update to 2.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.10.0
mcg (Red Hat package) - update to 5.10.0-72.el8
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
ovn21.12 (Red Hat package) - update to 21.12.0-25.el8fdp

External References

Related Security Bulletins