Observable discrepancy in Libgcrypt - CVE-2021-33560

 

Observable discrepancy in Libgcrypt - CVE-2021-33560

Published: September 17, 2021


Vulnerability identifier: #VU56684
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33560
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to observable discrepancy. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

Libgcrypt
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
HPE Helion Openstack
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
cflinuxfs3
libgcrypt (Red Hat package)
libgcrypt11
libgcrypt11-32bit
libgcrypt-debuginfo
libgcrypt-debugsource
libgcrypt20-debuginfo
libgcrypt-devel-debuginfo
libgcrypt-devel
libgcrypt20-hmac-32bit
libgcrypt20-hmac
libgcrypt20-debuginfo-32bit
libgcrypt20-32bit
libgcrypt20
libgcrypt20 (Ubuntu package)
libgcrypt20-32bit-debuginfo
libgcrypt
libgcrypt-help
dev-libs/libgcrypt
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Cloud Pak for Security (CP4S)
Migration Toolkit for Containers
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Juniper Cloud Native Router
Dell EMC VxRail Appliance
SecurID Authentication Manager
Junos cRPD

How to mitigate CVE-2021-33560

Install updates from vendor's website.

Libgcrypt - addressed in versions 1.8.8, 1.9.3
cflinuxfs3 - update to 0.258.0
libgcrypt (Red Hat package) - update to 1.8.5-6.el8
Cloud Pak for Security (CP4S) - update to 1.10.7.0
libgcrypt11 - update to 1.5.0-0.26.6.1
libgcrypt11-32bit - update to 1.5.0-0.26.6.1
libgcrypt-debuginfo - update to 1.5.0-0.26.6.1
libgcrypt-debugsource - addressed in versions 1.5.0-0.26.6.1, 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
Migration Toolkit for Containers - update to 1.5.4
libgcrypt20-debuginfo - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt-devel-debuginfo - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt-devel - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-hmac-32bit - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-hmac - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20-debuginfo-32bit - update to 1.6.1-16.77.1
libgcrypt20-32bit - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20 - addressed in versions 1.6.1-16.77.1, 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt20 (Ubuntu package) - addressed in versions 1.6.52ubuntu0.6+esm1, 1.8.1-4ubuntu1.3, 1.8.5-5ubuntu1.1, 1.8.7-2ubuntu2.1
libgcrypt20-32bit-debuginfo - addressed in versions 1.8.2-6.52.1, 1.8.2-8.39.1
libgcrypt - update to 1.8.6-3
libgcrypt-devel - update to 1.8.6-3
libgcrypt-debuginfo - update to 1.8.6-3
libgcrypt-debugsource - update to 1.8.6-3
libgcrypt-help - update to 1.8.6-3
libgcrypt - addressed in versions 1.8.8-1.fc33, 1.9.3-3.fc34
dev-libs/libgcrypt - update to 1.9.4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell EMC VxRail Appliance - update to 7.0.203
SecurID Authentication Manager - update to 8.5 Patch 5
Red Hat OpenStack - update to 16.2
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1

External References

Related Security Bulletins