UNIX symbolic link following in Binutils - CVE-2021-20197
Published: August 15, 2022
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue within the ar, objcopy, strip, ranlib utilities wen writing output. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Voice Gateway
SUSE Linux Enterprise Module for Packagehub Subpackages
bpftrace
bpftrace-tools
binutils (Red Hat package)
mingw-binutils
binutils
binutils-devel
binutils-debuginfo
binutils-debugsource
binutils-help
libctf-nobfd0-debuginfo
libctf0
libctf0-debuginfo
binutils-devel-32bit
libctf-nobfd0
binutils-gold
binutils-gold-debuginfo
cross-spu-binutils-debugsource
cross-spu-binutils-debuginfo
cross-ppc-binutils
cross-ppc-binutils-debuginfo
cross-ppc-binutils-debugsource
cross-spu-binutils
sys-devel/binutils
sys-libs/binutils-libs
PowerStore T
PowerStore X
How to mitigate CVE-2021-20197
Voice Gateway - update to 1.0.8.12
bpftrace - update to 0.11.4-3.2.1
bpftrace-tools - update to 0.11.4-3.2.1
binutils (Red Hat package) - update to 2.30-108.el8
mingw-binutils - update to 2.34-7.fc33
binutils - update to 2.34-9
binutils-devel - update to 2.34-9
binutils-debuginfo - update to 2.34-9
binutils-debugsource - update to 2.34-9
binutils-help - update to 2.34-9
binutils-debugsource - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-devel - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf-nobfd0-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf0 - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf0-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-devel-32bit - addressed in versions 2.37-6.23.1, 2.37-7.21.2
libctf-nobfd0 - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-gold - addressed in versions 2.37-7.21.2, 2.37-9.39.1
binutils-gold-debuginfo - addressed in versions 2.37-7.21.2, 2.37-9.39.1
cross-spu-binutils-debugsource - update to 2.37-9.39.1
cross-spu-binutils-debuginfo - update to 2.37-9.39.1
cross-ppc-binutils - update to 2.37-9.39.1
cross-ppc-binutils-debuginfo - update to 2.37-9.39.1
cross-ppc-binutils-debugsource - update to 2.37-9.39.1
cross-spu-binutils - update to 2.37-9.39.1
sys-devel/binutils - update to 2.38
sys-libs/binutils-libs - update to 2.38
PowerStore T - update to 3.2.1.0-1989710
PowerStore X - update to 3.2.1.0-1989710
External References
Related Security Bulletins
- Multiple vulnerabilities in GNU Binutils
- Gentoo update for GNU Binutils
- Red Hat Enterprise Linux 8 update for binutils
- Multiple vulnerabilities in Dell PowerStore Family
- openEuler 20.03 LTS SP1 update for binutils
- SUSE update for binutils
- SUSE update for binutils
- SUSE update for binutils
- Fedora 33 update for mingw-binutils
- Multiple vulnerabilities in IBM Voice Gateway