Out-of-bounds read in libjpeg-turbo - CVE-2021-29390

 

Out-of-bounds read in libjpeg-turbo - CVE-2021-29390

Published: September 11, 2023


Vulnerability identifier: #VU80613
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29390
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to heap-based buffer over-read within the decompress_smooth_data() function in jdcoefct.c. A remote attacker can pass specially crafted image to the application and perform a denial of service attack.


Affected software

libjpeg-turbo
Cloud Pak for Network Automation
Fedora
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
OpenShift API for Data Protection (OADP)
libjpeg-turbo (Red Hat package)
libjpeg-turbo-doc
turbojpeg-devel
turbojpeg
libjpeg-turbo-utils
libjpeg-turbo-devel
libjpeg-turbo
chromium
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
Red Hat Migration Toolkit for Applications
Red Hat OpenShift Container Platform

How to mitigate CVE-2021-29390

Install update from vendor's website.

Cloud Pak for Network Automation - update to 2.7.4
OpenShift API for Data Protection (OADP) - update to 1.3.2
libjpeg-turbo (Red Hat package) - update to 2.0.90-7.el9
libjpeg-turbo-doc - update to 2.0.90-7.0.1
turbojpeg-devel - update to 2.0.90-7.0.1
turbojpeg - update to 2.0.90-7.0.1
libjpeg-turbo-utils - update to 2.0.90-7.0.1
libjpeg-turbo-devel - update to 2.0.90-7.0.1
libjpeg-turbo - update to 2.0.90-7.0.1
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.16.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.15, 4.17.0
Red Hat Migration Toolkit for Applications - update to 6.2.3
chromium - addressed in versions 116.0.5845.179-1.el7, 116.0.5845.179-1.el8, 116.0.5845.179-1.el9, 116.0.5845.179-1.fc37, 116.0.5845.179-1.fc38, 116.0.5845.179-1.fc39, 116.0.5845.187-1.el7, 116.0.5845.187-1.el8, 116.0.5845.187-1.el9, 116.0.5845.187-1.fc37, 116.0.5845.187-1.fc38, 117.0.5938.62-1.el7, 117.0.5938.62-1.el8, 117.0.5938.62-1.el9, 117.0.5938.62-1.fc37, 117.0.5938.62-1.fc38, 117.0.5938.88-1.el7, 117.0.5938.88-1.el8, 117.0.5938.88-1.el9, 117.0.5938.88-1.fc37, 117.0.5938.92-2.el7, 117.0.5938.92-2.el8, 117.0.5938.92-2.el9, 117.0.5938.132-1.el7, 117.0.5938.132-1.el8, 117.0.5938.132-1.el9

External References

Related Security Bulletins