Use-after-free in selinux - CVE-2021-36085

 

Use-after-free in selinux - CVE-2021-36085

Published: April 27, 2022


Vulnerability identifier: #VU62661
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36085
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error within the __cil_verify_classperms() function in CIL compiler in SELinux. A local user can perform a denial of service (DoS) attack.

Affected software

selinux
cflinuxfs3
Amazon Linux AMI
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Ubuntu
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Red Hat OpenShift Serverless
OpenShift Virtualization
libsepol1 (Ubuntu package)
sepol-utils (Ubuntu package)
libsepol (Red Hat package)
libsepol

How to mitigate CVE-2021-36085

Install updates from vendor's website.

selinux - update to 3.3
cflinuxfs3 - update to 0.290.0
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
libsepol1 (Ubuntu package) - addressed in versions 2.7-1ubuntu0.1, 3.0-1ubuntu0.1, 3.1-1ubuntu2.1
sepol-utils (Ubuntu package) - addressed in versions 2.7-1ubuntu0.1, 3.0-1ubuntu0.1, 3.1-1ubuntu2.1
libsepol (Red Hat package) - update to 2.9-3.el8
libsepol - update to 3.3-2.fc35
libsepol - update to 3.4-3
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
OpenShift Virtualization - update to 4.11.0
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins