Buffer overflow in Go programming language - CVE-2021-41771
Published: July 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists in debug/macho of the Go standard library when using the debug/macho standard library (stdlib) and malformed binaries are parsed using Open or OpenFat. A remote attacker can send a specially crafted file to perform a denial of service attack.
Affected software
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
SUSE Linux Enterprise Module for Development Tools
openEuler
Astronomer with IBM
ObjectScale
IBM Netezza for Cloud Pak for Data
Dell PowerProtect Cyber Recovery
IBM MQ Operator
IBM Robotic Process Automation
Netcool Operations Insight
QRadar Suite
Splunk Enterprise
Red Hat OpenShift Serverless
openshift-serverless-clients (Red Hat package)
delve
golang
golang-help
golang-devel
go1.16-race
go1.16-doc
go1.16
go1.17-race
go1.17-doc
go1.17
golang-docs
golang-race
golang-misc
golang-src
golang-tests
golang-bin
go-toolset
Migration Toolkit for Containers
OpenShift Serverless Client
Brownfield Connectivity - Gateway
How to mitigate CVE-2021-41771
Astronomer with IBM - update to 1.0.1
ObjectScale - update to 1.3.0
IBM MQ Operator - update to 2.0.0
QRadar Suite - update to 1.10.17.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
Red Hat OpenShift Serverless - update to 1
openshift-serverless-clients (Red Hat package) - update to 1.1.0-2.el8
Netcool Operations Insight - update to 1.6.6
Migration Toolkit for Containers - update to 1.7.1
delve - update to 1.7.2-1
Brownfield Connectivity - Gateway - update to 1.10.1
golang - update to 1.15.7-6
golang-help - update to 1.15.7-6
golang-devel - update to 1.15.7-6
go1.16-race - update to 1.16.10-1.32.1
go1.16-doc - update to 1.16.10-1.32.1
go1.16 - update to 1.16.10-1.32.1
golang - addressed in versions 1.16.11-1.fc34, 1.16.11-1.fc35, 1.16.13-2.el7
golang - addressed in versions 1.16.15-1.37, 1.19.3-2
go1.17-race - update to 1.17.3-1.9.1
go1.17-doc - update to 1.17.3-1.9.1
go1.17 - update to 1.17.3-1.9.1
golang-docs - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-src - update to 1.17.7-1
golang-tests - update to 1.17.7-1
golang-bin - update to 1.17.7-1
go-toolset - update to 1.17.7-1
golang - update to 1.17.7-1
OpenShift Serverless Client - update to 1.22.0
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM MQ Operator
- Gentoo update for Go
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Siemens Brownfield Connectivity Gateway
- SUSE update for go1.17
- SUSE update for go1.16
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar Suite software
- openEuler update for golang
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Migration Toolkit for Containers 1.7
- Multiple vulnerabilities in OpenShift Serverless Client 1.22
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Fedora 35 update for golang
- Fedora 34 update for golang
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in IBM Netezza for Cloud Pak for Data (on Cloud)
- Anolis OS update for go-toolset:an8 module
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Astronomer with IBM