Input validation error in Go programming language - CVE-2021-29923
Published: September 22, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input in net.ParseIP and net.ParseCIDR, as the Go interpreter does not properly consider extraneous zero characters at the beginning
of an IP address octet. A remote attacker can
bypass access control that is based on IP addresses, because of
unexpected octal interpretation.
Affected software
Gentoo Linux
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
openEuler
golang-github-prometheus-promu (Red Hat package)
golang-github-vbatts-tar-split (Red Hat package)
butane (Red Hat package)
kubevirt (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
ignition (Red Hat package)
openshift-ansible (Red Hat package)
etcd (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
jenkins-2-plugins (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
openshift-serverless-clients (Red Hat package)
golang-qpid-apache (Red Hat package)
delve
golang
golang-help
golang-devel
go-toolset-1.15-golang (Red Hat package)
golang-bin
go-toolset
golang-tests
golang-race
golang-src
golang-misc
golang-docs
ovn21.12 (Red Hat package)
ObjectScale
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Asset Repository in IBM Cloud Pak for Integration (CP4I)
IBM Cloud Pak for Watson AIOps
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack for IBM Power
Red Hat OpenStack
IBM Robotic Process Automation
Operations Dashboard
Netcool Operations Insight
OpenShift Virtualization
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Cloud Private
IBM CICS TX Standard
Red Hat OpenShift Container Platform
OpenShift Serverless Client
Oracle TimesTen In-Memory Database
How to mitigate CVE-2021-29923
golang-github-prometheus-promu (Red Hat package) - update to 0.5.0-5.git642a960.el8
golang-github-vbatts-tar-split (Red Hat package) - update to 0.11.1-6.el8ost
butane (Red Hat package) - update to 0.13.1-2.rhaos4.9.el8
kubevirt (Red Hat package) - addressed in versions 2.6.8-211.el7, 2.6.8-211.el8, 4.8.3-251.el7, 4.8.3-251.el8
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
cri-tools (Red Hat package) - update to 1.22.0-2.el8
cri-o (Red Hat package) - addressed in versions 1.22.1-17.rhaos4.9.git3029b1d.2.el8, 1.22.1-17.rhaos4.9.git3029b1d.el7
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-4, 4.0.2
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
OpenShift Virtualization - addressed in versions 2.6.8, 4.8.3, 4.10.0
ignition (Red Hat package) - update to 2.12.0-3.rhaos4.9.el8
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.67, 3.68
IBM Cloud Private - addressed in versions 3.2.1.2203, 3.2.2.2203
openshift-ansible (Red Hat package) - update to 4.9.0-202202111950.p0.g4d833d3.assembly.stream.el7
etcd (Red Hat package) - update to 3.3.23-7.el8ost
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.7
openshift-clients (Red Hat package) - addressed in versions 4.9.0-202202140924.p0.g340e212.assembly.stream.el7, 4.9.0-202202140924.p0.g340e212.assembly.stream.el8
Red Hat OpenShift Container Platform - update to 4.9.22
openshift (Red Hat package) - addressed in versions 4.9.0-202202111950.p0.gb93fd35.assembly.stream.el7, 4.9.0-202202111950.p0.gb93fd35.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.9.1644822177-1.el8
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Red Hat OpenStack - update to 16.2
IBM Robotic Process Automation - update to 21.0.3.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-4, 2021.3.1
Asset Repository in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-3, 2021.2.1-1
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
openshift-serverless-clients (Red Hat package) - update to 0.26.0-2.el8
golang-qpid-apache (Red Hat package) - update to 0.32.0 rc1.9.el8ost
delve - update to 1.6.0-1
Netcool Operations Insight - update to 1.6.6
golang - update to 1.15.7-5
golang-help - update to 1.15.7-5
golang-devel - update to 1.15.7-5
go-toolset-1.15-golang (Red Hat package) - update to 1.15.14-2.el7_9
golang-bin - update to 1.16.12-1
go-toolset - update to 1.16.12-1
golang - update to 1.16.12-1
golang-tests - update to 1.16.12-1
golang-race - update to 1.16.12-1
golang-src - update to 1.16.12-1
golang-misc - update to 1.16.12-1
golang-docs - update to 1.16.12-1
golang - addressed in versions 1.17.7-1.el7, 1.18~rc1-2.fc36
OpenShift Serverless Client - update to 1.20.0
Red Hat OpenShift Serverless - update to 1.20.0
IBM Cloud Pak for Watson AIOps - update to 3.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.10.0
IBM CICS TX Standard - update to 11.1.0.0 ifix6
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
Oracle TimesTen In-Memory Database - update to 21.1.1.1.0
ovn21.12 (Red Hat package) - update to 21.12.0-25.el8fdp
External References
- https://github.com/golang/go/issues/43389
- https://github.com/golang/go/issues/30999
- https://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudis
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-016.md
- https://golang.org/pkg/net/#ParseCIDR
- https://go-review.googlesource.com/c/go/+/325829/
Related Security Bulletins
- Security restrictions bypass in Go programming language
- Red Hat Enterprise Linux 8.4 update for the go-toolset:rhel8 module
- Multiple vulnerabilities in IBM Watson Discovery for IBM Cloud Pak for Data
- Red Hat OpenShift Virtualization update for kubevirt
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Security restrictions bypass in Red Hat OpenShift Virtualization
- Multiple vulnerabilities in Oracle TimesTen In-Memory Database
- Red Hat OpenStack Platform 16 update for etcd
- Red Hat OpenStack Platform 16 update for etcd
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Red Hat OpenStack Platform 16.1 update for golang-qpid-apache
- Red Hat OpenStack Platform 16.1 update for golang-github-vbatts-tar-split
- Red Hat OpenStack Platform 16.2 update for golang-github-vbatts-tar-split
- Red Hat OpenStack Platform 16.2 update for golang-qpid-apache
- IBM Cloud Private update for Golang
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Gentoo update for Go
- Multiple vulnerabilities in IBM Cloud Pak for Integration
- Multiple vulnerabilities in IBM Operations Dashboard
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple Vulnerabilities in IBM CloudPak for Watson AIOPs
- Multiple vulnerabilities in Netcool Operations Insight
- Input validation error in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Red Hat Developer Tools update for go-toolset-1.15-golang
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar Suite software
- openEuler update for golang
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in OpenShift Serverless Client 1.20
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.10
- Fedora 36 update for golang
- Fedora EPEL 7 update for golang
- Anolis OS update for go-toolset:an8 module
- Multiple vulnerabilities in Dell ObjectScale