Infinite loop in elfutils - CVE-2021-33294

 

Infinite loop in elfutils - CVE-2021-33294

Published: August 31, 2023


Vulnerability identifier: #VU80176
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33294
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the handle_symtab() function in readelf.c. A remote attacker can consume all available system resources and trigger denial of service condition.


Affected software

elfutils
Ubuntu
openEuler
elfutils (Ubuntu package)
libasm1 (Ubuntu package)
libdw1 (Ubuntu package)
libelf1 (Ubuntu package)
elfutils-debugsource
elfutils-default-yama-scope
elfutils
elfutils-debuginfod-client-devel
elfutils-debuginfo
elfutils-devel
elfutils-libelf-devel
elfutils-libelf
elfutils-libs
elfutils-help
elfutils-debuginfod-client
elfutils-debuginfod
elfutils-extra
VMware Tanzu Operations Manager
VMware Tanzu Application Service for VMs
Isolation Segment
IBM CICS TX Advanced

How to mitigate CVE-2021-33294

Install update from vendor's website.

elfutils (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libasm1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libdw1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libelf1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
elfutils-debugsource - update to 0.180-14
elfutils-default-yama-scope - update to 0.180-14
elfutils - update to 0.180-14
elfutils-debuginfod-client-devel - update to 0.180-14
elfutils-debuginfo - update to 0.180-14
elfutils-devel - update to 0.180-14
elfutils-libelf-devel - update to 0.180-14
elfutils-libelf - update to 0.180-14
elfutils-libs - update to 0.180-14
elfutils-help - update to 0.180-14
elfutils-debuginfod-client - update to 0.180-14
elfutils-debuginfod - update to 0.180-14
elfutils-extra - update to 0.180-14
VMware Tanzu Operations Manager - update to 2.10.61
VMware Tanzu Application Service for VMs - addressed in versions 3.0.17, 4.0.9
Isolation Segment - addressed in versions 3.0.17, 4.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix24

External References

Related Security Bulletins