Integer overflow in cpio - CVE-2021-38185
Published: August 16, 2021 / Updated: January 30, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the "ds_fgetstr" parameter in "dstring.c". A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
cflinuxfs3
Enterprise SONiC
OpenShift Service Mesh
OpenShift Virtualization
Red Hat Advanced Cluster Management for Kubernetes
IBM Sterling Connect:Direct for UNIX
cpio (Red Hat package)
cpio (Ubuntu package)
cpio-debugsource
cpio
cpio-lang
cpio-debuginfo
cpio-mt
cpio-mt-debuginfo
app-arch/cpio
cpio-help
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Red Hat OpenShift Container Platform
How to mitigate CVE-2021-38185
cflinuxfs3 - update to 0.255.0
OpenShift Service Mesh - update to 2.1.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.11, 2.4.5
cpio (Red Hat package) - update to 2.12-11.el8
IBM Sterling Connect:Direct for UNIX - update to 6.2.0.4
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 7, 7.5.0 Update Pack 3
cpio (Ubuntu package) - addressed in versions Ubuntu Pro, 2.11+dfsg5ubuntu1.1+esm1, 2.12+dfsg-6ubuntu0.18.04.4, 2.13+dfsg-2ubuntu0.3, 2.13+dfsg-4ubuntu0.3
cpio-debugsource - addressed in versions 2.9-75.81.8.1, 2.9-75.81.14.1, 2.11-36.9.1, 2.11-36.15.1, 2.12-3.6.1
cpio - addressed in versions 2.9-75.81.8.1, 2.9-75.81.14.1, 2.11-36.9.1, 2.11-36.15.1, 2.12-3.6.1
cpio-lang - addressed in versions 2.9-75.81.8.1, 2.9-75.81.14.1, 2.11-36.9.1, 2.11-36.15.1, 2.12-3.6.1
cpio-debuginfo - addressed in versions 2.9-75.81.8.1, 2.9-75.81.14.1, 2.11-36.9.1, 2.11-36.15.1, 2.12-3.6.1
cpio-mt - update to 2.12-3.6.1
cpio-mt-debuginfo - update to 2.12-3.6.1
cpio - update to 2.12-11.0.1
app-arch/cpio - update to 2.13-r1
cpio - update to 2.13-4
cpio-debuginfo - update to 2.13-4
cpio-debugsource - update to 2.13-4
cpio-help - update to 2.13-4
cpio - update to 2.13-13
Enterprise SONiC - update to 4.1.2
Red Hat OpenShift Container Platform - update to 4.11.0
OpenShift Virtualization - update to 4.11.0
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in GNU cpio
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- Red Hat Enterprise Linux 8 update for cpio
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.1
- SUSE update for cpio
- SUSE update for cpio
- SUSE update for cpio
- SUSE update for cpio
- SUSE update for cpio
- Ubuntu update for cpio
- Ubuntu update for cpio
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.3
- Remote code execution in IBM Sterling Connect:Direct for UNIX Certified Container
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in IBM QRadar SIEM
- Ubuntu update for cpio
- Multiple vulnerabilities in Dell EMC Enterprise SONiC
- openEuler update for cpio
- Gentoo update for cpio
- Amazon Linux AMI update for cpio
- Anolis OS update for cpio
- Dell RecoverPoint for Virtual Machines update for third-party components