Input validation error in crypto - CVE-2021-43565
Published: June 29, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when parsing a Signer to ServerConfig.AddHostKey in cases where the Signer passed to AddHostKey does not implement AlgorithmSigner or the Signer passed to AddHostKey returns a key of type “ssh-rsa” from its PublicKey method. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
openSUSE Leap
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
QRadar Suite
Splunk Enterprise
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Automation Manager
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Operations Dashboard
Netcool Operations Insight
IBM Fusion HCI
Red Hat OpenStack
Database Operator for FoundationDB
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
ObjectScale
Dell EMC Streaming Data Platform
IBM Watson Machine Learning Accelerator
PowerStore T
PowerStore X
IBM Cloud Pak for Watson AIOps
Storage Ceph
Robotic Process Automation for Cloud Pak
Event Streams
SUSE Linux Enterprise Module for Packagehub Subpackages
kubevirt-manifests
kubevirt-virtctl
kubevirt-virtctl-debuginfo
containerd
containerd-ctr
golang
amazon-ssm-agent
mcg (Red Hat package)
docker
docker-debuginfo
docker-zsh-completion
docker-kubic-zsh-completion
docker-kubic-fish-completion
docker-kubic-bash-completion
docker-fish-completion
docker-bash-completion
docker-kubic-kubeadm-criconfig
docker-kubic-debuginfo
docker-kubic
IBM Cloud Pak for Multicloud Management
Dell EMC VxRail Appliance
AMQ Broker
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2021-43565
Red Hat OpenShift Serverless - update to 1.26.0
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.6, 2.4.3, 2.4.4, 2.4.5, 2.5.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.1.0
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-7, 2022.2.1-0
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-6, 2021.4.1-1
kubevirt-manifests - addressed in versions 0.40.0-5.17.2, 0.45.0-8.7.1, 0.49.0-150300.8.10.1
kubevirt-virtctl - addressed in versions 0.40.0-5.17.2, 0.45.0-8.7.1, 0.49.0-150300.8.10.1
kubevirt-virtctl-debuginfo - addressed in versions 0.40.0-5.17.2, 0.45.0-8.7.1, 0.49.0-150300.8.10.1
ObjectScale - update to 1.4.0
containerd - addressed in versions 1.5.11-16.57.1, 1.5.11-150000.68.1
containerd-ctr - update to 1.5.11-150000.68.1
Netcool Operations Insight - update to 1.6.9
Dell EMC Streaming Data Platform - update to 1.7.0
golang - update to 1.17.7-1.el7
IBM Cloud Pak for Multicloud Management - update to 2.3.5
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Fusion HCI - update to 2.7.0
PowerStore T - update to 3.2.1.0-1989710
PowerStore X - update to 3.2.1.0-1989710
amazon-ssm-agent - addressed in versions 3.2.1377.0-1, 3.2.1705.0-1
IBM Cloud Pak for Watson AIOps - update to 4.6.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.10.0
mcg (Red Hat package) - update to 5.10.0-72.el8
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
Storage Ceph - update to 7.1
AMQ Broker - update to 7.12.0
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
Red Hat OpenStack - update to 16.2.z
docker - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-debuginfo - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-fish-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-bash-completion - update to 20.10.14_ce-150000.163.1
docker-fish-completion - update to 20.10.14_ce-150000.163.1
docker-bash-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-kubeadm-criconfig - update to 20.10.14_ce-150000.163.1
docker-kubic-debuginfo - update to 20.10.14_ce-150000.163.1
docker-kubic - update to 20.10.14_ce-150000.163.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3
External References
Related Security Bulletins
- Denial of service in Go crypto
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat OpenStack 16.2
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Denial of service in Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Multiple vulnerabilities in Dell VxRail
- IBM Cloud Pak for Multicloud Management Infrastructure Management update for Go
- Multiple vulnerabilities in IBM Event Streams
- IBM CICS TX update for golang
- Multiple vulnerabilities in OpenShift Serverles
- Multiple vulnerabilities in Dell VxRail Appliance components
- SUSE update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-operator-container
- SUSE update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-operator-container
- SUSE update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container
- SUSE update for containerd, docker
- SUSE update for containerd, docker
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Input validation error in IBM Cloud Automation Manager
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell Streaming Data Platform
- Multiple vulnerabilities in Dell PowerStore Family
- Splunk Enterprise update for third-party packages
- Amazon Linux AMI update for amazon-ssm-agent
- Amazon Linux AMI update for amazon-ssm-agent
- Multiple vulnerabilities in IBM Storage Fusion
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in AMQ Broker 7.12
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.10
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.10
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2
- Fedora EPEL 7 update for golang
- Amazon Linux AMI update for amazon-ssm-agent
- Amazon Linux AMI update for amazon-ssm-agent
- Input validation error in IBM Operations Dashboard
- Multiple vulnerabilities in IBM Database Operator for FoundationDB