Allocation of Resources Without Limits or Throttling in Go programming language - CVE-2021-39293
Published: March 1, 2022 / Updated: June 2, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of archive/zip in Go programming language when processing archive header. A remote attacker can pass a specially crafted file to the application and perform a denial of service (DoS) attack.
Affected software
Astronomer with IBM
ObjectScale
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Dell PowerProtect Cyber Recovery
IBM MQ Operator
IBM Cloud Pak for Multicloud Management Monitoring
IBM Robotic Process Automation
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Security Services
Red Hat Advanced Cluster Security for Kubernetes
QRadar Suite
Splunk Enterprise
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
OpenShift Serverless Client
Fedora
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Development Tools
openEuler
openshift-serverless-clients (Red Hat package)
delve
golang-devel
golang-help
golang
go1.16-race
go1.16
go1.16-doc
golang-src
go-toolset
golang-bin
golang-race
golang-docs
golang-misc
golang-tests
Red Hat OpenShift Serverless
SCALANCE LPE9403
How to mitigate CVE-2021-39293
Astronomer with IBM - update to 1.0.1
ObjectScale - update to 1.3.0
IBM MQ Operator - addressed in versions 1.3.5, 2.0.0
QRadar Suite - update to 1.10.17.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat OpenShift Container Platform - update to 4.9.23
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
openshift-serverless-clients (Red Hat package) - update to 0.26.0-2.el8
Migration Toolkit for Containers - update to 1.6.5
Netcool Operations Insight - update to 1.6.6
delve - update to 1.7.2-1
golang-devel - update to 1.15.7-8
golang-help - update to 1.15.7-8
golang - update to 1.15.7-8
go1.16-race - update to 1.16.8-1.26.1
go1.16 - update to 1.16.8-1.26.1
go1.16-doc - update to 1.16.8-1.26.1
golang - update to 1.16.13-2.el7
golang-src - update to 1.17.7-1
go-toolset - update to 1.17.7-1
golang - update to 1.17.7-1
golang-bin - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-docs - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-tests - update to 1.17.7-1
OpenShift Serverless Client - update to 1.20.0
Red Hat OpenShift Serverless - update to 1.20.0
SCALANCE LPE9403 - update to 2.0
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
Related Security Bulletins
- Denial of service in Go programming language
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in Siemens SCALANCE LPE9403
- SUSE update for go1.16
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Security Services
- openEuler update for golang
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in OpenShift Serverless Client 1.20
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Multiple vulnerabilities in Migration Toolkit for Containers 1.6
- Fedora EPEL 7 update for golang
- Anolis OS update for go-toolset:an8 module
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Astronomer with IBM
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data