Link following in rpm - CVE-2021-35939

 

Link following in rpm - CVE-2021-35939

Published: August 15, 2023


Vulnerability identifier: #VU79523
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35939
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to escalate privileges on the system.

The vulnerability exist due to fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local privileged user who owns another ancestor directory could potentially use this flaw to gain root privileges.


Affected software

rpm
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
openEuler
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
Service Telemetry Framework
Service Interconnect
Cryostat
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
AppDynamics NodeJS Agent
Multicluster GlobalHub
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Security Verify Governance
Red Hat OpenStack
Red Hat OpenShift Serverless
OpenShift Container Platform for Windows Containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rpm (Red Hat package)
python3-rpm
rpm-devel
rpm
rpm-plugin-ima
rpm-build
rpm-plugin-fapolicyd
rpm-build-libs
rpm-libs
rpm-plugin-prioreset
rpm-cron
rpm-apidocs
rpm-sign
rpm-plugin-systemd-inhibit
rpm-plugin-syslog
rpm-plugin-selinux
python2-rpm
rpm-debugsource
rpm-debuginfo
rpm-help
app-arch/rpm
webMethods Managed File Transfer
Storage Ceph
Dell Data Protection Central
Red Hat OpenShift GitOps
IBM Qradar SIEM
AMQ Broker

How to mitigate CVE-2021-35939

Install updates from vendor's website.

rpm - update to 4.18.0
Red Hat OpenShift Builds - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.32.0
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Telemetry Framework - update to 1.5.4
Service Interconnect - update to 1.5.3
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.5, 2.9.3
Red Hat Advanced Cluster Security for Kubernetes - update to 4.3.5
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.15.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
OpenShift Container Platform for Windows Containers - addressed in versions 8.1.2, 9.0.1, 10.15.0
AppDynamics NodeJS Agent - update to 25.12.1
Multicluster GlobalHub - update to 1.0.2
Network Observability plugin for the Openshift Console - update to 1.5.0
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.0
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
rpm (Red Hat package) - addressed in versions 4.14.3-26.el8_6, 4.14.3-28.el8_8, 4.14.3-28.el8_9, 4.16.1.3-14.el9_0.1, 4.16.1.3-27.el9_3
python3-rpm - update to 4.14.3-27.0.5
rpm-devel - update to 4.14.3-27.0.5
rpm - update to 4.14.3-27.0.5
rpm-plugin-ima - update to 4.14.3-27.0.5
rpm-build - update to 4.14.3-27.0.5
rpm-plugin-fapolicyd - update to 4.14.3-27.0.5
rpm-build-libs - update to 4.14.3-27.0.5
rpm-libs - update to 4.14.3-27.0.5
rpm-plugin-prioreset - update to 4.14.3-27.0.5
rpm-cron - update to 4.14.3-27.0.5
rpm-apidocs - update to 4.14.3-27.0.5
rpm-sign - update to 4.14.3-27.0.5
rpm-plugin-systemd-inhibit - update to 4.14.3-27.0.5
rpm-plugin-syslog - update to 4.14.3-27.0.5
rpm-plugin-selinux - update to 4.14.3-27.0.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
rpm - update to 4.15.1-28
rpm-devel - update to 4.15.1-28
python2-rpm - update to 4.15.1-28
rpm-plugin-systemd-inhibit - update to 4.15.1-28
rpm-debugsource - update to 4.15.1-28
rpm-debuginfo - update to 4.15.1-28
rpm-libs - update to 4.15.1-28
rpm-build - update to 4.15.1-28
python3-rpm - update to 4.15.1-28
rpm-help - update to 4.15.1-28
rpm - update to 4.16.1.3-29
app-arch/rpm - update to 4.18.0
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
Storage Ceph - update to 6.1z5
Red Hat Migration Toolkit for Applications - update to 6.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
AMQ Broker - update to 7.12.0
IBM Security Verify Governance - update to 10.0.2.0.4
Red Hat OpenStack - update to 16.2
Dell Data Protection Central - update to 19.9

External References

Related Security Bulletins