Use-after-free in selinux - CVE-2021-36086
Published: April 27, 2022
Vulnerability identifier: #VU62662
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36086
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error within the cil_reset_classpermission() function in CIL compiler in SELinux. A local user can perform a denial of service (DoS) attack.Affected software
selinux
cflinuxfs3
Amazon Linux AMI
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Red Hat OpenShift Serverless
OpenShift Virtualization
libsepol1 (Ubuntu package)
sepol-utils (Ubuntu package)
libsepol (Red Hat package)
libsepol
libsepol-debugsource
libsepol-debuginfo
libsepol-devel
libsepol-help
cflinuxfs3
Amazon Linux AMI
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Red Hat OpenShift Serverless
OpenShift Virtualization
libsepol1 (Ubuntu package)
sepol-utils (Ubuntu package)
libsepol (Red Hat package)
libsepol
libsepol-debugsource
libsepol-debuginfo
libsepol-devel
libsepol-help
How to mitigate CVE-2021-36086
Install updates from vendor's website.
selinux - update to 3.3
cflinuxfs3 - update to 0.290.0
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
libsepol1 (Ubuntu package) - addressed in versions 2.7-1ubuntu0.1, 3.0-1ubuntu0.1, 3.1-1ubuntu2.1
sepol-utils (Ubuntu package) - addressed in versions 2.7-1ubuntu0.1, 3.0-1ubuntu0.1, 3.1-1ubuntu2.1
libsepol (Red Hat package) - update to 2.9-3.el8
libsepol - update to 3.1-8
libsepol-debugsource - update to 3.1-8
libsepol-debuginfo - update to 3.1-8
libsepol-devel - update to 3.1-8
libsepol-help - update to 3.1-8
libsepol - update to 3.3-2.fc35
libsepol - update to 3.4-3
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
OpenShift Virtualization - update to 4.11.0
Red Hat OpenStack - update to 16.2
cflinuxfs3 - update to 0.290.0
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
libsepol1 (Ubuntu package) - addressed in versions 2.7-1ubuntu0.1, 3.0-1ubuntu0.1, 3.1-1ubuntu2.1
sepol-utils (Ubuntu package) - addressed in versions 2.7-1ubuntu0.1, 3.0-1ubuntu0.1, 3.1-1ubuntu2.1
libsepol (Red Hat package) - update to 2.9-3.el8
libsepol - update to 3.1-8
libsepol-debugsource - update to 3.1-8
libsepol-debuginfo - update to 3.1-8
libsepol-devel - update to 3.1-8
libsepol-help - update to 3.1-8
libsepol - update to 3.3-2.fc35
libsepol - update to 3.4-3
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
OpenShift Virtualization - update to 4.11.0
Red Hat OpenStack - update to 16.2
External References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=32177
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/selinux/OSV-2021-536.yaml
- https://github.com/SELinuxProject/selinux/commit/c49a8ea09501ad66e799ea41b8154b6770fec2c8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U7ZYR3PIJ75N6U2IONJWCKZ5L2NKJTGR/
Related Security Bulletins
- Multiple vulnerabilities in SELinux
- Ubuntu update for libsepol
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in OpenShift Virtualization
- Red Hat Enterprise Linux 8 update for libsepol
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- openEuler update for libsepol
- Amazon Linux AMI update for libsepol
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Fedora 35 update for libsepol
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2