Input validation error in Go programming language - CVE-2021-29923

 

Input validation error in Go programming language - CVE-2021-29923

Published: September 22, 2021


Vulnerability identifier: #VU56829
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29923
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input in net.ParseIP and net.ParseCIDR, as the Go interpreter does not properly consider extraneous zero characters at the beginning of an IP address octet. A remote attacker can bypass access control that is based on IP addresses, because of unexpected octal interpretation.


Affected software

Go programming language
Gentoo Linux
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
openEuler
golang-github-prometheus-promu (Red Hat package)
golang-github-vbatts-tar-split (Red Hat package)
butane (Red Hat package)
kubevirt (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
ignition (Red Hat package)
openshift-ansible (Red Hat package)
etcd (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
jenkins-2-plugins (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
openshift-serverless-clients (Red Hat package)
golang-qpid-apache (Red Hat package)
delve
golang
golang-help
golang-devel
go-toolset-1.15-golang (Red Hat package)
golang-bin
go-toolset
golang-tests
golang-race
golang-src
golang-misc
golang-docs
ovn21.12 (Red Hat package)
ObjectScale
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Asset Repository in IBM Cloud Pak for Integration (CP4I)
IBM Cloud Pak for Watson AIOps
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack for IBM Power
Red Hat OpenStack
IBM Robotic Process Automation
Operations Dashboard
Netcool Operations Insight
OpenShift Virtualization
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Cloud Private
IBM CICS TX Standard
Red Hat OpenShift Container Platform
OpenShift Serverless Client
Oracle TimesTen In-Memory Database

How to mitigate CVE-2021-29923

Install updates from vendor's website.

Go programming language - update to 1.17
golang-github-prometheus-promu (Red Hat package) - update to 0.5.0-5.git642a960.el8
golang-github-vbatts-tar-split (Red Hat package) - update to 0.11.1-6.el8ost
butane (Red Hat package) - update to 0.13.1-2.rhaos4.9.el8
kubevirt (Red Hat package) - addressed in versions 2.6.8-211.el7, 2.6.8-211.el8, 4.8.3-251.el7, 4.8.3-251.el8
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
cri-tools (Red Hat package) - update to 1.22.0-2.el8
cri-o (Red Hat package) - addressed in versions 1.22.1-17.rhaos4.9.git3029b1d.2.el8, 1.22.1-17.rhaos4.9.git3029b1d.el7
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-4, 4.0.2
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
OpenShift Virtualization - addressed in versions 2.6.8, 4.8.3, 4.10.0
ignition (Red Hat package) - update to 2.12.0-3.rhaos4.9.el8
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.67, 3.68
IBM Cloud Private - addressed in versions 3.2.1.2203, 3.2.2.2203
openshift-ansible (Red Hat package) - update to 4.9.0-202202111950.p0.g4d833d3.assembly.stream.el7
etcd (Red Hat package) - update to 3.3.23-7.el8ost
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.7
openshift-clients (Red Hat package) - addressed in versions 4.9.0-202202140924.p0.g340e212.assembly.stream.el7, 4.9.0-202202140924.p0.g340e212.assembly.stream.el8
Red Hat OpenShift Container Platform - update to 4.9.22
openshift (Red Hat package) - addressed in versions 4.9.0-202202111950.p0.gb93fd35.assembly.stream.el7, 4.9.0-202202111950.p0.gb93fd35.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.9.1644822177-1.el8
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Red Hat OpenStack - update to 16.2
IBM Robotic Process Automation - update to 21.0.3.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-4, 2021.3.1
Asset Repository in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-3, 2021.2.1-1
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
openshift-serverless-clients (Red Hat package) - update to 0.26.0-2.el8
golang-qpid-apache (Red Hat package) - update to 0.32.0 rc1.9.el8ost
delve - update to 1.6.0-1
Netcool Operations Insight - update to 1.6.6
golang - update to 1.15.7-5
golang-help - update to 1.15.7-5
golang-devel - update to 1.15.7-5
go-toolset-1.15-golang (Red Hat package) - update to 1.15.14-2.el7_9
golang-bin - update to 1.16.12-1
go-toolset - update to 1.16.12-1
golang - update to 1.16.12-1
golang-tests - update to 1.16.12-1
golang-race - update to 1.16.12-1
golang-src - update to 1.16.12-1
golang-misc - update to 1.16.12-1
golang-docs - update to 1.16.12-1
golang - addressed in versions 1.17.7-1.el7, 1.18~rc1-2.fc36
OpenShift Serverless Client - update to 1.20.0
Red Hat OpenShift Serverless - update to 1.20.0
IBM Cloud Pak for Watson AIOps - update to 3.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.10.0
IBM CICS TX Standard - update to 11.1.0.0 ifix6
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
Oracle TimesTen In-Memory Database - update to 21.1.1.1.0
ovn21.12 (Red Hat package) - update to 21.12.0-25.el8fdp

External References

Related Security Bulletins