Observable discrepancy in Libgcrypt - CVE-2021-33560
Published: September 17, 2021
Vulnerability identifier: #VU56684
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33560
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to observable discrepancy. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Libgcrypt
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
HPE Helion Openstack
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
cflinuxfs3
libgcrypt (Red Hat package)
libgcrypt11
libgcrypt11-32bit
libgcrypt-debuginfo
libgcrypt-debugsource
libgcrypt20-debuginfo
libgcrypt-devel-debuginfo
libgcrypt-devel
libgcrypt20-hmac-32bit
libgcrypt20-hmac
libgcrypt20-debuginfo-32bit
libgcrypt20-32bit
libgcrypt20
libgcrypt20 (Ubuntu package)
libgcrypt20-32bit-debuginfo
libgcrypt
libgcrypt-help
dev-libs/libgcrypt
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Cloud Pak for Security (CP4S)
Migration Toolkit for Containers
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Juniper Cloud Native Router
Dell EMC VxRail Appliance
SecurID Authentication Manager
Junos cRPD
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
HPE Helion Openstack
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
cflinuxfs3
libgcrypt (Red Hat package)
libgcrypt11
libgcrypt11-32bit
libgcrypt-debuginfo
libgcrypt-debugsource
libgcrypt20-debuginfo
libgcrypt-devel-debuginfo
libgcrypt-devel
libgcrypt20-hmac-32bit
libgcrypt20-hmac
libgcrypt20-debuginfo-32bit
libgcrypt20-32bit
libgcrypt20
libgcrypt20 (Ubuntu package)
libgcrypt20-32bit-debuginfo
libgcrypt
libgcrypt-help
dev-libs/libgcrypt
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Cloud Pak for Security (CP4S)
Migration Toolkit for Containers
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Juniper Cloud Native Router
Dell EMC VxRail Appliance
SecurID Authentication Manager
Junos cRPD
How to mitigate CVE-2021-33560
Install updates from vendor's website.
Libgcrypt - addressed in versions 1.8.8, 1.9.3
cflinuxfs3 - update to 0.258.0
libgcrypt (Red Hat package) - update to 1.8.5-6.el8
Cloud Pak for Security (CP4S) - update to 1.10.7.0
libgcrypt11 - update to 1.5.0-0.26.6.1
libgcrypt11-32bit - update to 1.5.0-0.26.6.1
libgcrypt-debuginfo - update to 1.5.0-0.26.6.1
libgcrypt-debugsource - addressed in versions 1.5.0-0.26.6.1, 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
Migration Toolkit for Containers - update to 1.5.4
libgcrypt20-debuginfo - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt-devel-debuginfo - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt-devel - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-hmac-32bit - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-hmac - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-debuginfo-32bit - update to 1.6.1-16.77.1
libgcrypt20-32bit - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20 - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20 (Ubuntu package) - addressed in versions 1.6.52ubuntu0.6+esm1, 1.8.1-4ubuntu1.3, 1.8.5-5ubuntu1.1, 1.8.7-2ubuntu2.1
libgcrypt20-32bit-debuginfo - addressed in versions 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt - update to 1.8.6-3
libgcrypt-devel - update to 1.8.6-3
libgcrypt-debuginfo - update to 1.8.6-3
libgcrypt-debugsource - update to 1.8.6-3
libgcrypt-help - update to 1.8.6-3
libgcrypt - addressed in versions 1.8.8-1.fc33, 1.9.3-3.fc34
dev-libs/libgcrypt - update to 1.9.4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell EMC VxRail Appliance - update to 7.0.203
SecurID Authentication Manager - update to 8.5 Patch 5
Red Hat OpenStack - update to 16.2
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
cflinuxfs3 - update to 0.258.0
libgcrypt (Red Hat package) - update to 1.8.5-6.el8
Cloud Pak for Security (CP4S) - update to 1.10.7.0
libgcrypt11 - update to 1.5.0-0.26.6.1
libgcrypt11-32bit - update to 1.5.0-0.26.6.1
libgcrypt-debuginfo - update to 1.5.0-0.26.6.1
libgcrypt-debugsource - addressed in versions 1.5.0-0.26.6.1, 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
Migration Toolkit for Containers - update to 1.5.4
libgcrypt20-debuginfo - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt-devel-debuginfo - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt-devel - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-hmac-32bit - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-hmac - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-debuginfo-32bit - update to 1.6.1-16.77.1
libgcrypt20-32bit - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20 - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20 (Ubuntu package) - addressed in versions 1.6.52ubuntu0.6+esm1, 1.8.1-4ubuntu1.3, 1.8.5-5ubuntu1.1, 1.8.7-2ubuntu2.1
libgcrypt20-32bit-debuginfo - addressed in versions 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt - update to 1.8.6-3
libgcrypt-devel - update to 1.8.6-3
libgcrypt-debuginfo - update to 1.8.6-3
libgcrypt-debugsource - update to 1.8.6-3
libgcrypt-help - update to 1.8.6-3
libgcrypt - addressed in versions 1.8.8-1.fc33, 1.9.3-3.fc34
dev-libs/libgcrypt - update to 1.9.4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell EMC VxRail Appliance - update to 7.0.203
SecurID Authentication Manager - update to 8.5 Patch 5
Red Hat OpenStack - update to 16.2
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
External References
- https://dev.gnupg.org/T5466
- https://dev.gnupg.org/rCe8b7f10be275bcedb5fc05ed4837a89bfd605c61
- https://dev.gnupg.org/T5305
- https://dev.gnupg.org/T5328
- https://lists.debian.org/debian-lts-announce/2021/06/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7OAPCUGPF3VLA7QAJUQSL255D4ITVTL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BKKTOIGFW2SGN3DO2UHHVZ7MJSYN4AAB/
Related Security Bulletins
- Observable discrepancy in Libgcrypt
- Multiple vulnerabilities in cflinuxfs3
- Red Hat Enterprise Linux 8 update for libgcrypt
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Amazon Linux AMI update for libgcrypt
- SUSE update for libgcrypt
- SUSE update for libgcrypt
- SUSE update for libgcrypt
- SUSE update for libgcrypt
- Ubuntu update for libgcrypt20
- Ubuntu update for libgcrypt20
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Gentoo update for libgcrypt
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- openEuler 20.03 LTS SP1 update for libgcrypt
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Fedora 33 update for libgcrypt
- Fedora 34 update for libgcrypt
- SecurID Authentication Manager update for third-party components
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2