Integer overflow in gmp - CVE-2021-43618
Published: May 24, 2022
Vulnerability identifier: #VU63553
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2021-43618
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in mpz/inp_raw.c. A remote attacker can pass specially crafted data to the application, trigger integer overflow and cause a denial of service condition on the target system.
Affected software
gmp
cflinuxfs3
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
Business Automation Insights
Robotic Process Automation for Cloud Pak
My Cloud
WD Cloud
My Cloud PR2100
My Cloud PR4100
My Cloud EX2 Ultra
My Cloud EX4100
My Cloud EX2100
My Cloud DL4100
My Cloud Mirror G2
My Cloud DL2100
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE MicroOS
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
openEuler
My Cloud OS 5
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
Service Telemetry Framework
cert-manager Operator for Red Hat OpenShift
Cryostat
Dell Secure Connect Gateway
OpenShift Logging
Submariner
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat OpenShift Dev Spaces
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libgmp-dev (Ubuntu package)
libgmp10 (Ubuntu package)
libgmpxx4ldbl (Ubuntu package)
gmp-debugsource
gmp-devel
libgmpxx4
libgmpxx4-debuginfo
libgmp10
libgmp10-debuginfo
libgmp10-32bit
libgmp10-debuginfo-32bit
libgmp10-32bit-debuginfo
libgmpxx4-32bit-debuginfo
libgmpxx4-32bit
gmp-devel-32bit
gmp (Red Hat package)
gmp-debuginfo
gmp-c++
gmp
dev-libs/gmp
Network Observability plugin for the Openshift Console
Red Hat Ceph Storage
IBM Qradar SIEM
AMQ Broker
cflinuxfs3
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
Business Automation Insights
Robotic Process Automation for Cloud Pak
My Cloud
WD Cloud
My Cloud PR2100
My Cloud PR4100
My Cloud EX2 Ultra
My Cloud EX4100
My Cloud EX2100
My Cloud DL4100
My Cloud Mirror G2
My Cloud DL2100
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE MicroOS
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
openEuler
My Cloud OS 5
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
Service Telemetry Framework
cert-manager Operator for Red Hat OpenShift
Cryostat
Dell Secure Connect Gateway
OpenShift Logging
Submariner
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat OpenShift Dev Spaces
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libgmp-dev (Ubuntu package)
libgmp10 (Ubuntu package)
libgmpxx4ldbl (Ubuntu package)
gmp-debugsource
gmp-devel
libgmpxx4
libgmpxx4-debuginfo
libgmp10
libgmp10-debuginfo
libgmp10-32bit
libgmp10-debuginfo-32bit
libgmp10-32bit-debuginfo
libgmpxx4-32bit-debuginfo
libgmpxx4-32bit
gmp-devel-32bit
gmp (Red Hat package)
gmp-debuginfo
gmp-c++
gmp
dev-libs/gmp
Network Observability plugin for the Openshift Console
Red Hat Ceph Storage
IBM Qradar SIEM
AMQ Broker
How to mitigate CVE-2021-43618
Install updates from vendor's website.
cflinuxfs3 - update to 0.328.0
Red Hat OpenShift Builds - update to 1.0.1
Migration Toolkit for Runtimes - addressed in versions 1.2.5, 1.2.6
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3, 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.10.4, 1.11.3, 1.12.0, 1.12.1
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.1, 2.5.2
Guardium Data Security Center (GDSC) - update to 3.6.1
Red Hat OpenShift Container Platform - addressed in versions 4.11.59, 4.12.53, 4.12.58, 4.15.2, 4.15.3, 4.16.15, 4.16.44, 4.17.0
OpenShift Virtualization - addressed in versions 4.13.6, 4.14.1
Dell Secure Connect Gateway - update to 5.12.00.10
OpenShift Logging - addressed in versions 5.6.18, 5.7.13, 5.8.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - addressed in versions 7.6.8, 7.6.9
OpenShift Container Platform for Windows Containers - addressed in versions 9.0.1, 10.15.0
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
libgmp-dev (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
libgmp10 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
libgmpxx4ldbl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
Submariner - update to 0.18.5
Multicluster GlobalHub - update to 1.2.1
Network Observability plugin for the Openshift Console - update to 1.5.0
Red Hat OpenShift Serverless - update to 1.33.0
Multicluster Engine for Kubernetes - addressed in versions 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.10.5, 2.10.8, 2.11.4, 2.11.7, 2.12.0, 2.12.1, 2.12.3
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
Red Hat OpenShift Dev Spaces - addressed in versions 3.16.0, 3.17.0
gmp-debugsource - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
gmp-devel - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmpxx4 - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmpxx4-debuginfo - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10 - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-debuginfo - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-32bit - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-debuginfo-32bit - update to 5.1.3-4.3.1
Red Hat Ceph Storage - addressed in versions 5.3, 6.1
My Cloud OS 5 - update to 5.22.113
libgmp10-32bit-debuginfo - update to 6.1.2-4.9.1
libgmpxx4-32bit-debuginfo - update to 6.1.2-4.9.1
libgmpxx4-32bit - update to 6.1.2-4.9.1
gmp-devel-32bit - update to 6.1.2-4.9.1
gmp (Red Hat package) - addressed in versions 6.1.2-11.el8, 6.1.2-11.el8_6.1, 6.1.2-11.el8_8.1, 6.2.0-13.el9
Red Hat Migration Toolkit for Applications - addressed in versions 6.2, 7.0.3
gmp-debuginfo - update to 6.2.0-2
gmp-c++ - update to 6.2.0-2
gmp-debugsource - update to 6.2.0-2
gmp-devel - update to 6.2.0-2
gmp - update to 6.2.0-2
gmp-devel - update to 6.2.0-13.0.1
gmp-c++ - update to 6.2.0-13.0.1
gmp - update to 6.2.0-13.0.1
dev-libs/gmp - update to 6.2.1-r2
gmp - update to 6.2.1-2
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF02
AMQ Broker - update to 7.12.0
Red Hat OpenStack - update to 16.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
Red Hat OpenShift Builds - update to 1.0.1
Migration Toolkit for Runtimes - addressed in versions 1.2.5, 1.2.6
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3, 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.10.4, 1.11.3, 1.12.0, 1.12.1
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.1, 2.5.2
Guardium Data Security Center (GDSC) - update to 3.6.1
Red Hat OpenShift Container Platform - addressed in versions 4.11.59, 4.12.53, 4.12.58, 4.15.2, 4.15.3, 4.16.15, 4.16.44, 4.17.0
OpenShift Virtualization - addressed in versions 4.13.6, 4.14.1
Dell Secure Connect Gateway - update to 5.12.00.10
OpenShift Logging - addressed in versions 5.6.18, 5.7.13, 5.8.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - addressed in versions 7.6.8, 7.6.9
OpenShift Container Platform for Windows Containers - addressed in versions 9.0.1, 10.15.0
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
libgmp-dev (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
libgmp10 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
libgmpxx4ldbl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
Submariner - update to 0.18.5
Multicluster GlobalHub - update to 1.2.1
Network Observability plugin for the Openshift Console - update to 1.5.0
Red Hat OpenShift Serverless - update to 1.33.0
Multicluster Engine for Kubernetes - addressed in versions 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.10.5, 2.10.8, 2.11.4, 2.11.7, 2.12.0, 2.12.1, 2.12.3
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
Red Hat OpenShift Dev Spaces - addressed in versions 3.16.0, 3.17.0
gmp-debugsource - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
gmp-devel - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmpxx4 - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmpxx4-debuginfo - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10 - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-debuginfo - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-32bit - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-debuginfo-32bit - update to 5.1.3-4.3.1
Red Hat Ceph Storage - addressed in versions 5.3, 6.1
My Cloud OS 5 - update to 5.22.113
libgmp10-32bit-debuginfo - update to 6.1.2-4.9.1
libgmpxx4-32bit-debuginfo - update to 6.1.2-4.9.1
libgmpxx4-32bit - update to 6.1.2-4.9.1
gmp-devel-32bit - update to 6.1.2-4.9.1
gmp (Red Hat package) - addressed in versions 6.1.2-11.el8, 6.1.2-11.el8_6.1, 6.1.2-11.el8_8.1, 6.2.0-13.el9
Red Hat Migration Toolkit for Applications - addressed in versions 6.2, 7.0.3
gmp-debuginfo - update to 6.2.0-2
gmp-c++ - update to 6.2.0-2
gmp-debugsource - update to 6.2.0-2
gmp-devel - update to 6.2.0-2
gmp - update to 6.2.0-2
gmp-devel - update to 6.2.0-13.0.1
gmp-c++ - update to 6.2.0-13.0.1
gmp - update to 6.2.0-13.0.1
dev-libs/gmp - update to 6.2.1-r2
gmp - update to 6.2.1-2
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF02
AMQ Broker - update to 7.12.0
Red Hat OpenStack - update to 16.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
External References
Related Security Bulletins
- Denial of service in GMP
- Multiple vulnerabilities in Western Digital My Cloud OS 5
- SUSE update for gmp
- SUSE update for gmp
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Ubuntu update for gmp
- Multiple vulnerabilities in cflinuxfs3
- Ubuntu update for gmp
- Multiple vulnerabilities in Oracle Solaris third-party software
- Gentoo update for GMP
- Red Hat Enterprise Linux 9 update for gmp
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift 1.12
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift 1.11
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Multiple vulnerabilities in Red Hat Ceph Storage 6.1
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat Network Observability
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 10.15
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Red Hat Enterprise Linux 8.6 Extended Update Support update for gmp
- openEuler update for gmp
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 9.0
- Red Hat Enterprise Linux 8 update for gmp
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.5
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat build of Cryostat 2 on RHEL 8
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in IBM QRadar SIEM
- Red Hat Enterprise Linux 8 update for gmp
- Multiple vulnerabilities in OpenShift Logging 5.7
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in AMQ Broker 7.12
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.33
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat Ceph Storage 5
- Amazon Linux AMI update for gmp
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.8
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in Multicluster GlobalHub 1.2
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Anolis OS update for gmp
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Submariner 0.18
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0
- Multiple vulnerabilities in Red Hat OpenShift distributed tracing (RHOSDT) 3.2