Integer overflow in cpio - CVE-2021-38185

 

Integer overflow in cpio - CVE-2021-38185

Published: August 16, 2021 / Updated: January 30, 2024


Vulnerability identifier: #VU55853
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38185
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the "ds_fgetstr" parameter in "dstring.c". A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

cpio
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
cflinuxfs3
Enterprise SONiC
OpenShift Service Mesh
OpenShift Virtualization
Red Hat Advanced Cluster Management for Kubernetes
IBM Sterling Connect:Direct for UNIX
cpio (Red Hat package)
cpio (Ubuntu package)
cpio-debugsource
cpio
cpio-lang
cpio-debuginfo
cpio-mt
cpio-mt-debuginfo
app-arch/cpio
cpio-help
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Red Hat OpenShift Container Platform

How to mitigate CVE-2021-38185

Install update from vendor's website.

cpio - update to 2.14
cflinuxfs3 - update to 0.255.0
OpenShift Service Mesh - update to 2.1.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.11, 2.4.5
cpio (Red Hat package) - update to 2.12-11.el8
IBM Sterling Connect:Direct for UNIX - update to 6.2.0.4
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 7, 7.5.0 Update Pack 3
cpio (Ubuntu package) - addressed in versions Ubuntu Pro, 2.11+dfsg5ubuntu1.1+esm1, 2.12+dfsg-6ubuntu0.18.04.4, 2.13+dfsg-2ubuntu0.3, 2.13+dfsg-4ubuntu0.3
cpio-debugsource - addressed in versions 2.9-75.81.8.1, 2.9-75.81.14.1, 2.11-36.9.1, 2.11-36.15.1, 2.12-3.6.1
cpio - addressed in versions 2.9-75.81.8.1, 2.9-75.81.14.1, 2.11-36.9.1, 2.11-36.15.1, 2.12-3.6.1
cpio-lang - addressed in versions 2.9-75.81.8.1, 2.9-75.81.14.1, 2.11-36.9.1, 2.11-36.15.1, 2.12-3.6.1
cpio-debuginfo - addressed in versions 2.9-75.81.8.1, 2.9-75.81.14.1, 2.11-36.9.1, 2.11-36.15.1, 2.12-3.6.1
cpio-mt - update to 2.12-3.6.1
cpio-mt-debuginfo - update to 2.12-3.6.1
cpio - update to 2.12-11.0.1
app-arch/cpio - update to 2.13-r1
cpio - update to 2.13-4
cpio-debuginfo - update to 2.13-4
cpio-debugsource - update to 2.13-4
cpio-help - update to 2.13-4
cpio - update to 2.13-13
Enterprise SONiC - update to 4.1.2
Red Hat OpenShift Container Platform - update to 4.11.0
OpenShift Virtualization - update to 4.11.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins