NULL pointer dereference in crypto - CVE-2020-29652
Published: November 21, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when processing an authentication request message for the “gssapi-with-mic” method. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
ObjectScale
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Storage Ceph
IBM Cloud Pak System
Splunk Enterprise
IBM MQ Operator
OpenShift Virtualization
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2020-29652
ObjectScale - update to 1.3.0
IBM Cloud Pak System - update to 2.3.3.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.1
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.4.0
OpenShift Virtualization - update to 4.8.0
Storage Ceph - update to 7.1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
External References
Related Security Bulletins
- Denial of service in Go Crypto
- IBM CICS TX update for golang
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in Dell ObjectScale