Buffer overflow in Go programming language - CVE-2021-41771

 

Buffer overflow in Go programming language - CVE-2021-41771

Published: July 11, 2022


Vulnerability identifier: #VU65080
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41771
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists in debug/macho of the Go standard library when using the debug/macho standard library (stdlib) and malformed binaries are parsed using Open or OpenFat. A remote attacker can send a specially crafted file to perform a denial of service attack.


Affected software

Go programming language
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
SUSE Linux Enterprise Module for Development Tools
openEuler
Astronomer with IBM
ObjectScale
IBM Netezza for Cloud Pak for Data
Dell PowerProtect Cyber Recovery
IBM MQ Operator
IBM Robotic Process Automation
Netcool Operations Insight
QRadar Suite
Splunk Enterprise
Red Hat OpenShift Serverless
openshift-serverless-clients (Red Hat package)
delve
golang
golang-help
golang-devel
go1.16-race
go1.16-doc
go1.16
go1.17-race
go1.17-doc
go1.17
golang-docs
golang-race
golang-misc
golang-src
golang-tests
golang-bin
go-toolset
Migration Toolkit for Containers
OpenShift Serverless Client
Brownfield Connectivity - Gateway

How to mitigate CVE-2021-41771

Install updates from vendor's website.

Go programming language - addressed in versions 1.16.10, 1.17.3
Astronomer with IBM - update to 1.0.1
ObjectScale - update to 1.3.0
IBM MQ Operator - update to 2.0.0
QRadar Suite - update to 1.10.17.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
Red Hat OpenShift Serverless - update to 1
openshift-serverless-clients (Red Hat package) - update to 1.1.0-2.el8
Netcool Operations Insight - update to 1.6.6
Migration Toolkit for Containers - update to 1.7.1
delve - update to 1.7.2-1
Brownfield Connectivity - Gateway - update to 1.10.1
golang - update to 1.15.7-6
golang-help - update to 1.15.7-6
golang-devel - update to 1.15.7-6
go1.16-race - update to 1.16.10-1.32.1
go1.16-doc - update to 1.16.10-1.32.1
go1.16 - update to 1.16.10-1.32.1
golang - addressed in versions 1.16.11-1.fc34, 1.16.11-1.fc35, 1.16.13-2.el7
golang - addressed in versions 1.16.15-1.37, 1.19.3-2
go1.17-race - update to 1.17.3-1.9.1
go1.17-doc - update to 1.17.3-1.9.1
go1.17 - update to 1.17.3-1.9.1
golang-docs - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-src - update to 1.17.7-1
golang-tests - update to 1.17.7-1
golang-bin - update to 1.17.7-1
go-toolset - update to 1.17.7-1
golang - update to 1.17.7-1
OpenShift Serverless Client - update to 1.22.0
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins