Use of a broken or risky cryptographic algorithm in Libgcrypt - CVE-2021-40528

 

Use of a broken or risky cryptographic algorithm in Libgcrypt - CVE-2021-40528

Published: September 17, 2021 / Updated: July 20, 2022


Vulnerability identifier: #VU56685
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-40528
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to use of a broken or risky cryptographic algorithm in the ElGamal implementation. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

Libgcrypt
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Oracle Linux
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
openEuler
cflinuxfs3
IBM supplied MQ Advanced container images
IBM Cloud Pak for Watson AIOps
Dell Data Protection Central
Submariner
Gatekeeper Operator
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM Security Verify Governance
IBM Robotic Process Automation
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Red Hat OpenStack
Juniper Cloud Native Router
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Ceph Storage
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Security Edge Protection Proxy
libgcrypt20 (Ubuntu package)
libgcrypt-devel
libgcrypt
libgcrypt-debugsource
libgcrypt-debuginfo
libgcrypt-help
dev-libs/libgcrypt
Red Hat OpenShift Serverless
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Junos cRPD

How to mitigate CVE-2021-40528

Install updates from vendor's website.

Libgcrypt - update to 1.9.4
cflinuxfs3 - update to 0.258.0
Submariner - update to 0.13.0
Gatekeeper Operator - update to 0.2
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.4, 1.1.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.0.1
IBM MQ Operator - addressed in versions 1.3.6, 2.0.1
Migration Toolkit for Containers - addressed in versions 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.12, 2.4.6, 2.5.1
Red Hat Advanced Cluster Security for Kubernetes - update to 3.71
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
OpenShift Logging - addressed in versions 5.2.13, 5.3.10, 5.4.3
IBM supplied MQ Advanced container images - addressed in versions 9.2.0.6-r1, 9.3.0.0-r2
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Robotic Process Automation - update to 21.0.3.1
Netcool Operations Insight - update to 1.6.7
libgcrypt20 (Ubuntu package) - addressed in versions 1.6.52ubuntu0.6+esm1, 1.8.1-4ubuntu1.3, 1.8.5-5ubuntu1.1, 1.8.7-2ubuntu2.1
libgcrypt-devel - update to 1.8.5-7
libgcrypt - update to 1.8.5-7
libgcrypt-debugsource - update to 1.8.6-4
libgcrypt-devel - update to 1.8.6-4
libgcrypt-debuginfo - update to 1.8.6-4
libgcrypt - update to 1.8.6-4
libgcrypt-help - update to 1.8.6-4
dev-libs/libgcrypt - update to 1.9.4
Red Hat OpenShift Serverless - update to 1.24.0
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.0
OpenShift Virtualization - update to 4.11.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
App Connect Enterprise Certified Container - addressed in versions 5.0.1, 5.1.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 8, 7.5.0 Update Pack 4
Red Hat OpenStack - update to 16.2.z
Dell Data Protection Central - update to 19.9
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins