Allocation of Resources Without Limits or Throttling in Go programming language - CVE-2021-39293

 

Allocation of Resources Without Limits or Throttling in Go programming language - CVE-2021-39293

Published: March 1, 2022 / Updated: June 2, 2022


Vulnerability identifier: #VU60921
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39293
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of archive/zip in Go programming language when processing archive header. A remote attacker can pass a specially crafted file to the application and perform a denial of service (DoS) attack.


Affected software

Go programming language
Astronomer with IBM
ObjectScale
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Dell PowerProtect Cyber Recovery
IBM MQ Operator
IBM Cloud Pak for Multicloud Management Monitoring
IBM Robotic Process Automation
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Security Services
Red Hat Advanced Cluster Security for Kubernetes
QRadar Suite
Splunk Enterprise
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
OpenShift Serverless Client
Fedora
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Development Tools
openEuler
openshift-serverless-clients (Red Hat package)
delve
golang-devel
golang-help
golang
go1.16-race
go1.16
go1.16-doc
golang-src
go-toolset
golang-bin
golang-race
golang-docs
golang-misc
golang-tests
Red Hat OpenShift Serverless
SCALANCE LPE9403

How to mitigate CVE-2021-39293

Install updates from vendor's website.

Go programming language - addressed in versions 1.16.8, 1.17.1
Astronomer with IBM - update to 1.0.1
ObjectScale - update to 1.3.0
IBM MQ Operator - addressed in versions 1.3.5, 2.0.0
QRadar Suite - update to 1.10.17.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat OpenShift Container Platform - update to 4.9.23
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
openshift-serverless-clients (Red Hat package) - update to 0.26.0-2.el8
Migration Toolkit for Containers - update to 1.6.5
Netcool Operations Insight - update to 1.6.6
delve - update to 1.7.2-1
golang-devel - update to 1.15.7-8
golang-help - update to 1.15.7-8
golang - update to 1.15.7-8
go1.16-race - update to 1.16.8-1.26.1
go1.16 - update to 1.16.8-1.26.1
go1.16-doc - update to 1.16.8-1.26.1
golang - update to 1.16.13-2.el7
golang-src - update to 1.17.7-1
go-toolset - update to 1.17.7-1
golang - update to 1.17.7-1
golang-bin - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-docs - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-tests - update to 1.17.7-1
OpenShift Serverless Client - update to 1.20.0
Red Hat OpenShift Serverless - update to 1.20.0
SCALANCE LPE9403 - update to 2.0
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins