Out-of-bounds read in Go Text - CVE-2021-38561

 

Out-of-bounds read in Go Text - CVE-2021-38561

Published: July 7, 2022


Vulnerability identifier: #VU65006
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38561
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.


Affected software

Go Text
Submariner
OpenShift Logging
Astronomer with IBM
DB2 Data Management Console
Planning Analytics Cartridge for Cloud Pak for Data
DB2 Data Management Console on CPD
ObjectScale
IBM Planning Analytics Workspace
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Database Operator for FoundationDB
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
OpenShift Developer Tools and Services
IBM CICS TX Advanced
IBM CICS TX Standard
Fedora
Ubuntu
Splunk Enterprise
Event Streams
Cloud Pak for Security (CP4S)
golang-x-text-dev (Ubuntu package)
golang-golang-x-text-dev (Ubuntu package)
golang-x-net
golang-x-text
kubevirt (Red Hat package)
OpenShift Virtualization

How to mitigate CVE-2021-38561

Install updates from vendor's website.

Go Text - update to 0.3.7
Submariner - update to 0.13.0
Astronomer with IBM - update to 1.0.1
DB2 Data Management Console - update to 3.1.13.1
Red Hat OpenShift Container Platform - addressed in versions 4.6.61, 4.9.48, 4.11.0, 4.11.3, 4.11.5, 4.11.25, 4.11.26, 4.11.27, 4.11.28, 4.11.29, 4.11.43, 4.11.46, 4.12.0, 4.12.5, 4.13.0
DB2 Data Management Console on CPD - update to 5.1.2
OpenShift Logging - addressed in versions 5.2.13, 5.3.10, 5.4.3
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.1.0
golang-x-text-dev (Ubuntu package) - update to 0.0~git20170627.0.6353ef0-1ubuntu2.1
golang-golang-x-text-dev (Ubuntu package) - addressed in versions 0.0~git20170627.0.6353ef0-1ubuntu2.1, 0.3.2-4ubuntu0.1, 0.3.7-1ubuntu0.20.04.1, 0.3.7-1ubuntu0.22.10.1
golang-x-net - update to 0-0.60.20200807gitab34263.el8
golang-x-text - update to 0.3.7-1.el8
ObjectScale - update to 1.4.0
Cloud Pak for Security (CP4S) - update to 1.10.10.0
IBM Planning Analytics Workspace - update to 2.0.84
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Database Operator for FoundationDB - update to 4.6
OpenShift Virtualization - addressed in versions 4.11.0, 4.11.1, 4.12.0
kubevirt (Red Hat package) - addressed in versions 4.12.0-1057.el7, 4.12.0-1057.el8
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3

External References

Related Security Bulletins