Link following in rpm - CVE-2021-35938

 

Link following in rpm - CVE-2021-35938

Published: August 15, 2023


Vulnerability identifier: #VU79521
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35938
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to escalate privileges on the system.

The vulnerability occurs when rpm sets the desired permissions and credentials after installing a file. A local privileged user can use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system.


Affected software

rpm
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
openEuler
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
Service Telemetry Framework
Service Interconnect
Cryostat
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
AppDynamics NodeJS Agent
Multicluster GlobalHub
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Security Verify Governance
Red Hat OpenStack
Red Hat OpenShift Serverless
OpenShift Container Platform for Windows Containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rpm (Red Hat package)
python3-rpm
rpm-devel
rpm
rpm-plugin-ima
rpm-build
rpm-plugin-fapolicyd
rpm-build-libs
rpm-libs
rpm-plugin-prioreset
rpm-cron
rpm-apidocs
rpm-sign
rpm-plugin-systemd-inhibit
rpm-plugin-syslog
rpm-plugin-selinux
python2-rpm
rpm-debugsource
rpm-debuginfo
rpm-help
app-arch/rpm
webMethods Managed File Transfer
Storage Ceph
Dell Data Protection Central
Red Hat OpenShift GitOps
IBM Qradar SIEM
AMQ Broker

How to mitigate CVE-2021-35938

Install updates from vendor's website.

rpm - update to 4.18.0
Red Hat OpenShift Builds - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.32.0
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Telemetry Framework - update to 1.5.4
Service Interconnect - update to 1.5.3
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.5, 2.9.3
Red Hat Advanced Cluster Security for Kubernetes - update to 4.3.5
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.15.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
OpenShift Container Platform for Windows Containers - addressed in versions 8.1.2, 9.0.1, 10.15.0
AppDynamics NodeJS Agent - update to 25.12.1
Multicluster GlobalHub - update to 1.0.2
Network Observability plugin for the Openshift Console - update to 1.5.0
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.0
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
rpm (Red Hat package) - addressed in versions 4.14.3-26.el8_6, 4.14.3-28.el8_8, 4.14.3-28.el8_9, 4.16.1.3-14.el9_0.1, 4.16.1.3-27.el9_3
python3-rpm - update to 4.14.3-27.0.5
rpm-devel - update to 4.14.3-27.0.5
rpm - update to 4.14.3-27.0.5
rpm-plugin-ima - update to 4.14.3-27.0.5
rpm-build - update to 4.14.3-27.0.5
rpm-plugin-fapolicyd - update to 4.14.3-27.0.5
rpm-build-libs - update to 4.14.3-27.0.5
rpm-libs - update to 4.14.3-27.0.5
rpm-plugin-prioreset - update to 4.14.3-27.0.5
rpm-cron - update to 4.14.3-27.0.5
rpm-apidocs - update to 4.14.3-27.0.5
rpm-sign - update to 4.14.3-27.0.5
rpm-plugin-systemd-inhibit - update to 4.14.3-27.0.5
rpm-plugin-syslog - update to 4.14.3-27.0.5
rpm-plugin-selinux - update to 4.14.3-27.0.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
rpm - update to 4.15.1-28
rpm-devel - update to 4.15.1-28
python2-rpm - update to 4.15.1-28
rpm-plugin-systemd-inhibit - update to 4.15.1-28
rpm-debugsource - update to 4.15.1-28
rpm-debuginfo - update to 4.15.1-28
rpm-libs - update to 4.15.1-28
rpm-build - update to 4.15.1-28
python3-rpm - update to 4.15.1-28
rpm-help - update to 4.15.1-28
rpm - update to 4.16.1.3-29
app-arch/rpm - update to 4.18.0
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
Red Hat Migration Toolkit for Applications - update to 6.2
Storage Ceph - update to 7.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
AMQ Broker - update to 7.12.0
IBM Security Verify Governance - update to 10.0.2.0.4
Red Hat OpenStack - update to 16.2
Dell Data Protection Central - update to 19.9

External References

Related Security Bulletins