Integer overflow in gmp - CVE-2021-43618

 

Integer overflow in gmp - CVE-2021-43618

Published: May 24, 2022


Vulnerability identifier: #VU63553
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2021-43618
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow in mpz/inp_raw.c. A remote attacker can pass specially crafted data to the application, trigger integer overflow and cause a denial of service condition on the target system.


Affected software

gmp
cflinuxfs3
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
Business Automation Insights
Robotic Process Automation for Cloud Pak
My Cloud
WD Cloud
My Cloud PR2100
My Cloud PR4100
My Cloud EX2 Ultra
My Cloud EX4100
My Cloud EX2100
My Cloud DL4100
My Cloud Mirror G2
My Cloud DL2100
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE MicroOS
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
openEuler
My Cloud OS 5
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
Service Telemetry Framework
cert-manager Operator for Red Hat OpenShift
Cryostat
Dell Secure Connect Gateway
OpenShift Logging
Submariner
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat OpenShift Dev Spaces
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libgmp-dev (Ubuntu package)
libgmp10 (Ubuntu package)
libgmpxx4ldbl (Ubuntu package)
gmp-debugsource
gmp-devel
libgmpxx4
libgmpxx4-debuginfo
libgmp10
libgmp10-debuginfo
libgmp10-32bit
libgmp10-debuginfo-32bit
libgmp10-32bit-debuginfo
libgmpxx4-32bit-debuginfo
libgmpxx4-32bit
gmp-devel-32bit
gmp (Red Hat package)
gmp-debuginfo
gmp-c++
gmp
dev-libs/gmp
Network Observability plugin for the Openshift Console
Red Hat Ceph Storage
IBM Qradar SIEM
AMQ Broker

How to mitigate CVE-2021-43618

Install updates from vendor's website.

cflinuxfs3 - update to 0.328.0
Red Hat OpenShift Builds - update to 1.0.1
Migration Toolkit for Runtimes - addressed in versions 1.2.5, 1.2.6
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3, 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.10.4, 1.11.3, 1.12.0, 1.12.1
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.1, 2.5.2
Guardium Data Security Center (GDSC) - update to 3.6.1
Red Hat OpenShift Container Platform - addressed in versions 4.11.59, 4.12.53, 4.12.58, 4.15.2, 4.15.3, 4.16.15, 4.16.44, 4.17.0
OpenShift Virtualization - addressed in versions 4.13.6, 4.14.1
Dell Secure Connect Gateway - update to 5.12.00.10
OpenShift Logging - addressed in versions 5.6.18, 5.7.13, 5.8.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - addressed in versions 7.6.8, 7.6.9
OpenShift Container Platform for Windows Containers - addressed in versions 9.0.1, 10.15.0
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
libgmp-dev (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
libgmp10 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
libgmpxx4ldbl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:6.1.2+dfsg-2ubuntu0.1, 2:6.2.0+dfsg-4ubuntu0.1
Submariner - update to 0.18.5
Multicluster GlobalHub - update to 1.2.1
Network Observability plugin for the Openshift Console - update to 1.5.0
Red Hat OpenShift Serverless - update to 1.33.0
Multicluster Engine for Kubernetes - addressed in versions 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.10.5, 2.10.8, 2.11.4, 2.11.7, 2.12.0, 2.12.1, 2.12.3
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
Red Hat OpenShift Dev Spaces - addressed in versions 3.16.0, 3.17.0
gmp-debugsource - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
gmp-devel - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmpxx4 - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmpxx4-debuginfo - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10 - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-debuginfo - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-32bit - addressed in versions 5.1.3-4.3.1, 6.1.2-4.9.1
libgmp10-debuginfo-32bit - update to 5.1.3-4.3.1
Red Hat Ceph Storage - addressed in versions 5.3, 6.1
My Cloud OS 5 - update to 5.22.113
libgmp10-32bit-debuginfo - update to 6.1.2-4.9.1
libgmpxx4-32bit-debuginfo - update to 6.1.2-4.9.1
libgmpxx4-32bit - update to 6.1.2-4.9.1
gmp-devel-32bit - update to 6.1.2-4.9.1
gmp (Red Hat package) - addressed in versions 6.1.2-11.el8, 6.1.2-11.el8_6.1, 6.1.2-11.el8_8.1, 6.2.0-13.el9
Red Hat Migration Toolkit for Applications - addressed in versions 6.2, 7.0.3
gmp-debuginfo - update to 6.2.0-2
gmp-c++ - update to 6.2.0-2
gmp-debugsource - update to 6.2.0-2
gmp-devel - update to 6.2.0-2
gmp - update to 6.2.0-2
gmp-devel - update to 6.2.0-13.0.1
gmp-c++ - update to 6.2.0-13.0.1
gmp - update to 6.2.0-13.0.1
dev-libs/gmp - update to 6.2.1-r2
gmp - update to 6.2.1-2
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF02
AMQ Broker - update to 7.12.0
Red Hat OpenStack - update to 16.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001

External References

Related Security Bulletins