Infinite loop in elfutils - CVE-2021-33294
Published: August 31, 2023
Vulnerability identifier: #VU80176
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33294
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the handle_symtab() function in readelf.c. A remote attacker can consume all available system resources and trigger denial of service condition.
Affected software
elfutils
Ubuntu
openEuler
elfutils (Ubuntu package)
libasm1 (Ubuntu package)
libdw1 (Ubuntu package)
libelf1 (Ubuntu package)
elfutils-debugsource
elfutils-default-yama-scope
elfutils
elfutils-debuginfod-client-devel
elfutils-debuginfo
elfutils-devel
elfutils-libelf-devel
elfutils-libelf
elfutils-libs
elfutils-help
elfutils-debuginfod-client
elfutils-debuginfod
elfutils-extra
VMware Tanzu Operations Manager
VMware Tanzu Application Service for VMs
Isolation Segment
IBM CICS TX Advanced
Ubuntu
openEuler
elfutils (Ubuntu package)
libasm1 (Ubuntu package)
libdw1 (Ubuntu package)
libelf1 (Ubuntu package)
elfutils-debugsource
elfutils-default-yama-scope
elfutils
elfutils-debuginfod-client-devel
elfutils-debuginfo
elfutils-devel
elfutils-libelf-devel
elfutils-libelf
elfutils-libs
elfutils-help
elfutils-debuginfod-client
elfutils-debuginfod
elfutils-extra
VMware Tanzu Operations Manager
VMware Tanzu Application Service for VMs
Isolation Segment
IBM CICS TX Advanced
How to mitigate CVE-2021-33294
Install update from vendor's website.
elfutils (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libasm1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libdw1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libelf1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
elfutils-debugsource - update to 0.180-14
elfutils-default-yama-scope - update to 0.180-14
elfutils - update to 0.180-14
elfutils-debuginfod-client-devel - update to 0.180-14
elfutils-debuginfo - update to 0.180-14
elfutils-devel - update to 0.180-14
elfutils-libelf-devel - update to 0.180-14
elfutils-libelf - update to 0.180-14
elfutils-libs - update to 0.180-14
elfutils-help - update to 0.180-14
elfutils-debuginfod-client - update to 0.180-14
elfutils-debuginfod - update to 0.180-14
elfutils-extra - update to 0.180-14
VMware Tanzu Operations Manager - update to 2.10.61
VMware Tanzu Application Service for VMs - addressed in versions 3.0.17, 4.0.9
Isolation Segment - addressed in versions 3.0.17, 4.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix24
libasm1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libdw1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libelf1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
elfutils-debugsource - update to 0.180-14
elfutils-default-yama-scope - update to 0.180-14
elfutils - update to 0.180-14
elfutils-debuginfod-client-devel - update to 0.180-14
elfutils-debuginfo - update to 0.180-14
elfutils-devel - update to 0.180-14
elfutils-libelf-devel - update to 0.180-14
elfutils-libelf - update to 0.180-14
elfutils-libs - update to 0.180-14
elfutils-help - update to 0.180-14
elfutils-debuginfod-client - update to 0.180-14
elfutils-debuginfod - update to 0.180-14
elfutils-extra - update to 0.180-14
VMware Tanzu Operations Manager - update to 2.10.61
VMware Tanzu Application Service for VMs - addressed in versions 3.0.17, 4.0.9
Isolation Segment - addressed in versions 3.0.17, 4.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix24