Buffer overflow in Go programming language - CVE-2021-38297

 

Buffer overflow in Go programming language - CVE-2021-38297

Published: October 21, 2021 / Updated: January 28, 2024


Vulnerability identifier: #VU57579
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38297
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.


Affected software

Go programming language
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Development Tools
openSUSE Leap
openEuler
ObjectScale
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Event Streams in IBM Cloud Pak for Integration
IBM Robotic Process Automation
Netcool Operations Insight
openshift-serverless-clients (Red Hat package)
delve
golang-help
golang-devel
golang
go1.16-doc
go1.16-race
go1.16
go1.17
go1.17-doc
go1.17-race
golang-tests
golang-src
golang-misc
golang-docs
golang-race
golang-bin
go-toolset
git-lfs
google-guest-agent
google-osconfig-agent
OpenShift Serverless Client
Red Hat OpenShift Serverless

How to mitigate CVE-2021-38297

Install update from vendor's website.

Go programming language - addressed in versions 1.16.9, 1.17.2
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
openshift-serverless-clients (Red Hat package) - update to 0.26.0-2.el8
Netcool Operations Insight - update to 1.6.6
delve - update to 1.7.2-1
golang-help - update to 1.15.7-5
golang-devel - update to 1.15.7-5
golang - update to 1.15.7-5
go1.16-doc - update to 1.16.9-1.29.1
go1.16-race - update to 1.16.9-1.29.1
go1.16 - update to 1.16.9-1.29.1
golang - addressed in versions 1.16.11-1.fc34, 1.16.11-1.fc35, 1.16.13-2.el7
golang - addressed in versions 1.16.15-1.37, 1.19.3-2
go1.17 - update to 1.17.2-1.6.2
go1.17-doc - update to 1.17.2-1.6.2
go1.17-race - update to 1.17.2-1.6.2
golang-tests - update to 1.17.7-1
golang-src - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-docs - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-bin - update to 1.17.7-1
golang - update to 1.17.7-1
go-toolset - update to 1.17.7-1
OpenShift Serverless Client - update to 1.20.0
Red Hat OpenShift Serverless - update to 1.20.0
git-lfs - update to 2.10.0-2.el7
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
google-guest-agent - addressed in versions 20230221.00-1.29.1, 20230221.00-150000.1.34.1
google-osconfig-agent - addressed in versions 20230222.00-1.20.1, 20230222.00-150000.1.27.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins