Input validation error in crypto - CVE-2021-43565

 

Input validation error in crypto - CVE-2021-43565

Published: June 29, 2022


Vulnerability identifier: #VU64805
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43565
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when parsing a Signer to ServerConfig.AddHostKey in cases where the Signer passed to AddHostKey does not implement AlgorithmSigner or the Signer passed to AddHostKey returns a key of type “ssh-rsa” from its PublicKey method. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

crypto
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
openSUSE Leap
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
QRadar Suite
Splunk Enterprise
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Automation Manager
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Operations Dashboard
Netcool Operations Insight
IBM Fusion HCI
Red Hat OpenStack
Database Operator for FoundationDB
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
ObjectScale
Dell EMC Streaming Data Platform
IBM Watson Machine Learning Accelerator
PowerStore T
PowerStore X
IBM Cloud Pak for Watson AIOps
Storage Ceph
Robotic Process Automation for Cloud Pak
Event Streams
SUSE Linux Enterprise Module for Packagehub Subpackages
kubevirt-manifests
kubevirt-virtctl
kubevirt-virtctl-debuginfo
containerd
containerd-ctr
golang
amazon-ssm-agent
mcg (Red Hat package)
docker
docker-debuginfo
docker-zsh-completion
docker-kubic-zsh-completion
docker-kubic-fish-completion
docker-kubic-bash-completion
docker-fish-completion
docker-bash-completion
docker-kubic-kubeadm-criconfig
docker-kubic-debuginfo
docker-kubic
IBM Cloud Pak for Multicloud Management
Dell EMC VxRail Appliance
AMQ Broker
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2021-43565

Install updates from vendor's website.

crypto - update to 0.0.0-20211202192323-5770296d904e
Red Hat OpenShift Serverless - update to 1.26.0
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.6, 2.4.3, 2.4.4, 2.4.5, 2.5.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.1.0
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-7, 2022.2.1-0
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-6, 2021.4.1-1
kubevirt-manifests - addressed in versions 0.40.0-5.17.2, 0.45.0-8.7.1, 0.49.0-150300.8.10.1
kubevirt-virtctl - addressed in versions 0.40.0-5.17.2, 0.45.0-8.7.1, 0.49.0-150300.8.10.1
kubevirt-virtctl-debuginfo - addressed in versions 0.40.0-5.17.2, 0.45.0-8.7.1, 0.49.0-150300.8.10.1
ObjectScale - update to 1.4.0
containerd - addressed in versions 1.5.11-16.57.1, 1.5.11-150000.68.1
containerd-ctr - update to 1.5.11-150000.68.1
Netcool Operations Insight - update to 1.6.9
Dell EMC Streaming Data Platform - update to 1.7.0
golang - update to 1.17.7-1.el7
IBM Cloud Pak for Multicloud Management - update to 2.3.5
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Fusion HCI - update to 2.7.0
PowerStore T - update to 3.2.1.0-1989710
PowerStore X - update to 3.2.1.0-1989710
amazon-ssm-agent - addressed in versions 3.2.1377.0-1, 3.2.1705.0-1
IBM Cloud Pak for Watson AIOps - update to 4.6.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.10.0
mcg (Red Hat package) - update to 5.10.0-72.el8
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
Storage Ceph - update to 7.1
AMQ Broker - update to 7.12.0
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
Red Hat OpenStack - update to 16.2.z
docker - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-debuginfo - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-fish-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-bash-completion - update to 20.10.14_ce-150000.163.1
docker-fish-completion - update to 20.10.14_ce-150000.163.1
docker-bash-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-kubeadm-criconfig - update to 20.10.14_ce-150000.163.1
docker-kubic-debuginfo - update to 20.10.14_ce-150000.163.1
docker-kubic - update to 20.10.14_ce-150000.163.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3

External References

Related Security Bulletins