Memory leak in libcap - CVE-2023-2602

 

Memory leak in libcap - CVE-2023-2602

Published: June 1, 2023


Vulnerability identifier: #VU76757
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2602
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in the error handling in the __wrap_pthread_create() function. A remote attacker can send a specially crafted request, exploit vulnerability to exhaust the process memory and cause a denial of service condition.


Affected software

libcap
webMethods Managed File Transfer
ObjectScale
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
Service Interconnect
VMware Tanzu Application Service for VMs
Isolation Segment
Run Once Duration Override Operator for Red Hat OpenShift
Red Hat OpenShift Kernel Module Management
Service Telemetry Framework
OpenShift Pipelines
cert-manager Operator for Red Hat OpenShift
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
DevWorkspace Operator
Netcool Operations Insight
IBM MQ Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Node Health Check Operator
Self Node Remediation Operator
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Node Maintenance Operator
VMware Tanzu Operations Manager
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
AMQ Broker
IBM Security Guardium
libcap2 (Ubuntu package)
libcap2-bin (Ubuntu package)
libcap
libcap-devel
libcap (Red Hat package)
libcap-help
libcap-debugsource
libcap-debuginfo
libpsx2-32bit
libcap2-32bit-debuginfo
libpsx2-32bit-debuginfo
libcap-progs
libcap2-32bit
libcap2
libcap2-debuginfo
libpsx2
libpsx2-debuginfo
libcap-progs-debuginfo
Dell EMC VxRail Appliance
Operational Decision Manager

How to mitigate CVE-2023-2602

Install updates from vendor's website.

libcap - update to 2.69
Node Health Check Operator - update to 0.4.1
Self Node Remediation Operator - addressed in versions 0.5.1, 0.7.1
Red Hat OpenShift Serverless - update to 1.30.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Red Hat OpenShift Kernel Module Management - update to 1.1.2
OpenShift API for Data Protection (OADP) - update to 1.1.6
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - addressed in versions 1.1.3, 1.2.0
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.13, 1.8.0
OpenShift Pipelines - addressed in versions 1.10.6, 1.11.2
cert-manager Operator for Red Hat OpenShift - update to 1.11.5
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7, 2.5.8
OpenShift Service Mesh - addressed in versions 2.2.10, 2.4.3, 2.4.8, 2.5.2
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.7, 2.7.7, 2.8.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.0.5
Red Hat OpenShift Container Platform - addressed in versions 4.11.54, 4.12.45, 4.13.24, 4.14.4
OpenShift Virtualization - update to 4.12.9
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.13.3, 4.14.0
Node Maintenance Operator - update to 5.0.1
Red Hat Migration Toolkit for Applications - update to 6.2.1
AMQ Broker - update to 7.11.1
Red Hat OpenStack - update to 17.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
DevWorkspace Operator - update to 0.22
ObjectScale - update to 1.4.0
Network Observability plugin for the Openshift Console - update to 1.4.0
Netcool Operations Insight - update to 1.6.12
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
Cloud Pak for Network Automation - update to 2.6.5
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
libcap2 (Ubuntu package) - addressed in versions 1:2.32-1ubuntu0.1, 1:2.44-1ubuntu0.22.04.1, 1:2.44-1ubuntu0.22.10.1, 1:2.66-3ubuntu2.1
libcap2-bin (Ubuntu package) - addressed in versions 1:2.32-1ubuntu0.1, 1:2.44-1ubuntu0.22.04.1, 1:2.44-1ubuntu0.22.10.1, 1:2.66-3ubuntu2.1
libcap - update to 2.48-2
libcap-devel - update to 2.48-5
libcap - update to 2.48-5
libcap (Red Hat package) - addressed in versions 2.48-5.el8_8, 2.48-9.el9_2
libcap - addressed in versions 2.48-7.fc38, 2.48-8.fc39
libcap - update to 2.61-5
libcap-help - update to 2.61-5
libcap-devel - update to 2.61-5
libcap-debugsource - update to 2.61-5
libcap-debuginfo - update to 2.61-5
libpsx2-32bit - update to 2.63-150400.3.3.1
libcap2-32bit-debuginfo - update to 2.63-150400.3.3.1
libpsx2-32bit-debuginfo - update to 2.63-150400.3.3.1
libcap-progs - update to 2.63-150400.3.3.1
libcap2-32bit - update to 2.63-150400.3.3.1
libcap-devel - update to 2.63-150400.3.3.1
libcap-debugsource - update to 2.63-150400.3.3.1
libcap2 - update to 2.63-150400.3.3.1
libcap2-debuginfo - update to 2.63-150400.3.3.1
libpsx2 - update to 2.63-150400.3.3.1
libpsx2-debuginfo - update to 2.63-150400.3.3.1
libcap-progs-debuginfo - update to 2.63-150400.3.3.1
VMware Tanzu Operations Manager - update to 3.0.12
IBM Cloud Transformation Advisor - update to 3.7.0
IBM Cloud Pak for Watson AIOps - update to 3.7.2
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.0, 5.1.0
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
Dell EMC VxRail Appliance - update to 8.0.120
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 49, 8.11.0.1 Interim fix 26, 8.12.0 Interim fix 8
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12

External References

Related Security Bulletins