Buffer overflow in Go programming language - CVE-2021-38297
Published: October 21, 2021 / Updated: January 28, 2024
Vulnerability identifier: #VU57579
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38297
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
Affected software
Go programming language
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Development Tools
openSUSE Leap
openEuler
ObjectScale
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Event Streams in IBM Cloud Pak for Integration
IBM Robotic Process Automation
Netcool Operations Insight
openshift-serverless-clients (Red Hat package)
delve
golang-help
golang-devel
golang
go1.16-doc
go1.16-race
go1.16
go1.17
go1.17-doc
go1.17-race
golang-tests
golang-src
golang-misc
golang-docs
golang-race
golang-bin
go-toolset
git-lfs
google-guest-agent
google-osconfig-agent
OpenShift Serverless Client
Red Hat OpenShift Serverless
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Development Tools
openSUSE Leap
openEuler
ObjectScale
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
IBM Event Streams in IBM Cloud Pak for Integration
IBM Robotic Process Automation
Netcool Operations Insight
openshift-serverless-clients (Red Hat package)
delve
golang-help
golang-devel
golang
go1.16-doc
go1.16-race
go1.16
go1.17
go1.17-doc
go1.17-race
golang-tests
golang-src
golang-misc
golang-docs
golang-race
golang-bin
go-toolset
git-lfs
google-guest-agent
google-osconfig-agent
OpenShift Serverless Client
Red Hat OpenShift Serverless
How to mitigate CVE-2021-38297
Install update from vendor's website.
Go programming language - addressed in versions 1.16.9, 1.17.2
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
openshift-serverless-clients (Red Hat package) - update to 0.26.0-2.el8
Netcool Operations Insight - update to 1.6.6
delve - update to 1.7.2-1
golang-help - update to 1.15.7-5
golang-devel - update to 1.15.7-5
golang - update to 1.15.7-5
go1.16-doc - update to 1.16.9-1.29.1
go1.16-race - update to 1.16.9-1.29.1
go1.16 - update to 1.16.9-1.29.1
golang - addressed in versions 1.16.11-1.fc34, 1.16.11-1.fc35, 1.16.13-2.el7
golang - addressed in versions 1.16.15-1.37, 1.19.3-2
go1.17 - update to 1.17.2-1.6.2
go1.17-doc - update to 1.17.2-1.6.2
go1.17-race - update to 1.17.2-1.6.2
golang-tests - update to 1.17.7-1
golang-src - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-docs - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-bin - update to 1.17.7-1
golang - update to 1.17.7-1
go-toolset - update to 1.17.7-1
OpenShift Serverless Client - update to 1.20.0
Red Hat OpenShift Serverless - update to 1.20.0
git-lfs - update to 2.10.0-2.el7
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
google-guest-agent - addressed in versions 20230221.00-1.29.1, 20230221.00-150000.1.34.1
google-osconfig-agent - addressed in versions 20230222.00-1.20.1, 20230222.00-150000.1.27.1
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
openshift-serverless-clients (Red Hat package) - update to 0.26.0-2.el8
Netcool Operations Insight - update to 1.6.6
delve - update to 1.7.2-1
golang-help - update to 1.15.7-5
golang-devel - update to 1.15.7-5
golang - update to 1.15.7-5
go1.16-doc - update to 1.16.9-1.29.1
go1.16-race - update to 1.16.9-1.29.1
go1.16 - update to 1.16.9-1.29.1
golang - addressed in versions 1.16.11-1.fc34, 1.16.11-1.fc35, 1.16.13-2.el7
golang - addressed in versions 1.16.15-1.37, 1.19.3-2
go1.17 - update to 1.17.2-1.6.2
go1.17-doc - update to 1.17.2-1.6.2
go1.17-race - update to 1.17.2-1.6.2
golang-tests - update to 1.17.7-1
golang-src - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-docs - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-bin - update to 1.17.7-1
golang - update to 1.17.7-1
go-toolset - update to 1.17.7-1
OpenShift Serverless Client - update to 1.20.0
Red Hat OpenShift Serverless - update to 1.20.0
git-lfs - update to 2.10.0-2.el7
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
google-guest-agent - addressed in versions 20230221.00-1.29.1, 20230221.00-150000.1.34.1
google-osconfig-agent - addressed in versions 20230222.00-1.20.1, 20230222.00-150000.1.27.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Buffer overflow in Go programming language
- Buffer overflow in IBM Event Streams in IBM Cloud Pak for Integration
- SUSE update for go1.16
- SUSE update for go1.17
- Gentoo update for Go
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Netcool Operations Insight
- SUSE update for google-guest-agent
- SUSE update for google-osconfig-agent
- SUSE update for google-osconfig-agent
- SUSE update for google-guest-agent
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar Suite software
- openEuler update for golang
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in OpenShift Serverless Client 1.20
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Fedora 35 update for golang
- Fedora 34 update for golang
- Fedora EPEL 7 update for golang
- Fedora EPEL 7 update for git-lfs
- Anolis OS update for go-toolset:an8 module
- Multiple vulnerabilities in Dell ObjectScale