Input validation error in Go programming language - CVE-2021-41772
Published: August 4, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in archive/zip Reader.Open. A remote attacker can pass specially crafted ZIP archive containing an invalid name or an empty filename field to the application and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
SUSE Linux Enterprise Module for Development Tools
ObjectScale
Astronomer with IBM
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Netezza for Cloud Pak for Data
Dell PowerProtect Cyber Recovery
QRadar Suite
Splunk Enterprise
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
OpenShift Serverless Client
IBM Robotic Process Automation
Netcool Operations Insight
Red Hat OpenShift Serverless
openshift-serverless-clients (Red Hat package)
delve
go1.16
go1.16-doc
go1.16-race
golang
go1.17
go1.17-race
go1.17-doc
go-toolset
golang-race
golang-bin
golang-docs
golang-misc
golang-src
golang-tests
Brownfield Connectivity - Gateway
How to mitigate CVE-2021-41772
ObjectScale - update to 1.3.0
Astronomer with IBM - update to 1.0.1
QRadar Suite - update to 1.10.17.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat OpenShift Container Platform - update to 4.12.4
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Robotic Process Automation - update to 21.0.3.1
Red Hat OpenShift Serverless - update to 1
openshift-serverless-clients (Red Hat package) - update to 1.1.0-2.el8
Netcool Operations Insight - update to 1.6.6
Migration Toolkit for Containers - update to 1.7.1
delve - update to 1.7.2-1
Brownfield Connectivity - Gateway - update to 1.10.1
go1.16 - update to 1.16.10-1.32.1
go1.16-doc - update to 1.16.10-1.32.1
go1.16-race - update to 1.16.10-1.32.1
golang - addressed in versions 1.16.11-1.fc34, 1.16.11-1.fc35, 1.16.13-2.el7
golang - addressed in versions 1.16.15-1.37, 1.19.3-2
go1.17 - update to 1.17.3-1.9.1
go1.17-race - update to 1.17.3-1.9.1
go1.17-doc - update to 1.17.3-1.9.1
go-toolset - update to 1.17.7-1
golang - update to 1.17.7-1
golang-race - update to 1.17.7-1
golang-bin - update to 1.17.7-1
golang-docs - update to 1.17.7-1
golang-misc - update to 1.17.7-1
golang-src - update to 1.17.7-1
golang-tests - update to 1.17.7-1
OpenShift Serverless Client - update to 1.22.0
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
- https://groups.google.com/g/golang-announce/c/0fM21h43arc
- https://security.netapp.com/advisory/ntap-20211210-0003/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4OFS3M3OFB24SWPTIAPARKGPUMQVUY6Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ON7BQRRJZBOR5TJHURBAB3WLF4YXFC6Z/
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.gentoo.org/glsa/202208-02
Related Security Bulletins
- Denial of service in Go programming language
- Gentoo update for Go
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in Siemens Brownfield Connectivity Gateway
- SUSE update for go1.17
- SUSE update for go1.16
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar Suite software
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Migration Toolkit for Containers 1.7
- Multiple vulnerabilities in OpenShift Serverless Client 1.22
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Fedora 35 update for golang
- Fedora 34 update for golang
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in IBM Netezza for Cloud Pak for Data (on Cloud)
- Anolis OS update for go-toolset:an8 module
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Astronomer with IBM
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data