Infinite loop in xz - CVE-2021-29482

 

Infinite loop in xz - CVE-2021-29482

Published: March 27, 2024


Vulnerability identifier: #VU87849
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29482
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due the function readUvarint used to read the xz container format may not terminate a loop providing malicious input. A remote attacker can consume all available system resources and cause denial of service conditions.


Affected software

xz
OpenShift API for Data Protection (OADP)
IBM Cloud Pak for Watson AIOps
OpenShift Virtualization
Red Hat OpenStack

How to mitigate CVE-2021-29482

Install updates from vendor's website.

xz - update to 0.5.8
OpenShift API for Data Protection (OADP) - update to 1.0.1
IBM Cloud Pak for Watson AIOps - update to 4.4.0
OpenShift Virtualization - update to 4.8.0
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins