Out-of-bounds read in Go Text - CVE-2021-38561
Published: July 7, 2022
Vulnerability identifier: #VU65006
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38561
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Affected software
Go Text
Submariner
OpenShift Logging
Astronomer with IBM
DB2 Data Management Console
Planning Analytics Cartridge for Cloud Pak for Data
DB2 Data Management Console on CPD
ObjectScale
IBM Planning Analytics Workspace
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Database Operator for FoundationDB
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
OpenShift Developer Tools and Services
IBM CICS TX Advanced
IBM CICS TX Standard
Fedora
Ubuntu
Splunk Enterprise
Event Streams
Cloud Pak for Security (CP4S)
golang-x-text-dev (Ubuntu package)
golang-golang-x-text-dev (Ubuntu package)
golang-x-net
golang-x-text
kubevirt (Red Hat package)
OpenShift Virtualization
Submariner
OpenShift Logging
Astronomer with IBM
DB2 Data Management Console
Planning Analytics Cartridge for Cloud Pak for Data
DB2 Data Management Console on CPD
ObjectScale
IBM Planning Analytics Workspace
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Database Operator for FoundationDB
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
OpenShift Developer Tools and Services
IBM CICS TX Advanced
IBM CICS TX Standard
Fedora
Ubuntu
Splunk Enterprise
Event Streams
Cloud Pak for Security (CP4S)
golang-x-text-dev (Ubuntu package)
golang-golang-x-text-dev (Ubuntu package)
golang-x-net
golang-x-text
kubevirt (Red Hat package)
OpenShift Virtualization
How to mitigate CVE-2021-38561
Install updates from vendor's website.
Go Text - update to 0.3.7
Submariner - update to 0.13.0
Astronomer with IBM - update to 1.0.1
DB2 Data Management Console - update to 3.1.13.1
Red Hat OpenShift Container Platform - addressed in versions 4.6.61, 4.9.48, 4.11.0, 4.11.3, 4.11.5, 4.11.25, 4.11.26, 4.11.27, 4.11.28, 4.11.29, 4.11.43, 4.11.46, 4.12.0, 4.12.5, 4.13.0
DB2 Data Management Console on CPD - update to 5.1.2
OpenShift Logging - addressed in versions 5.2.13, 5.3.10, 5.4.3
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.1.0
golang-x-text-dev (Ubuntu package) - update to 0.0~git20170627.0.6353ef0-1ubuntu2.1
golang-golang-x-text-dev (Ubuntu package) - addressed in versions 0.0~git20170627.0.6353ef0-1ubuntu2.1, 0.3.2-4ubuntu0.1, 0.3.7-1ubuntu0.20.04.1, 0.3.7-1ubuntu0.22.10.1
golang-x-net - update to 0-0.60.20200807gitab34263.el8
golang-x-text - update to 0.3.7-1.el8
ObjectScale - update to 1.4.0
Cloud Pak for Security (CP4S) - update to 1.10.10.0
IBM Planning Analytics Workspace - update to 2.0.84
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Database Operator for FoundationDB - update to 4.6
OpenShift Virtualization - addressed in versions 4.11.0, 4.11.1, 4.12.0
kubevirt (Red Hat package) - addressed in versions 4.12.0-1057.el7, 4.12.0-1057.el8
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3
Submariner - update to 0.13.0
Astronomer with IBM - update to 1.0.1
DB2 Data Management Console - update to 3.1.13.1
Red Hat OpenShift Container Platform - addressed in versions 4.6.61, 4.9.48, 4.11.0, 4.11.3, 4.11.5, 4.11.25, 4.11.26, 4.11.27, 4.11.28, 4.11.29, 4.11.43, 4.11.46, 4.12.0, 4.12.5, 4.13.0
DB2 Data Management Console on CPD - update to 5.1.2
OpenShift Logging - addressed in versions 5.2.13, 5.3.10, 5.4.3
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.1.0
golang-x-text-dev (Ubuntu package) - update to 0.0~git20170627.0.6353ef0-1ubuntu2.1
golang-golang-x-text-dev (Ubuntu package) - addressed in versions 0.0~git20170627.0.6353ef0-1ubuntu2.1, 0.3.2-4ubuntu0.1, 0.3.7-1ubuntu0.20.04.1, 0.3.7-1ubuntu0.22.10.1
golang-x-net - update to 0-0.60.20200807gitab34263.el8
golang-x-text - update to 0.3.7-1.el8
ObjectScale - update to 1.4.0
Cloud Pak for Security (CP4S) - update to 1.10.10.0
IBM Planning Analytics Workspace - update to 2.0.84
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Database Operator for FoundationDB - update to 4.6
OpenShift Virtualization - addressed in versions 4.11.0, 4.11.1, 4.12.0
kubevirt (Red Hat package) - addressed in versions 4.12.0-1057.el7, 4.12.0-1057.el8
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3
External References
Related Security Bulletins
- Denial of service in Go Text
- Multiple vulnerabilities in OpenShift Developer Tools and Services
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.4
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in Openshift Logging 5.2
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Logging Subsystem for Red Hat OpenShift
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.6
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in OpenShift Virtualization 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- OpenShift Container Platform 4.11 update for Go Text
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- OpenShift Container Platform 4.11 update for Golang
- Ubuntu update for golang-golang-x-text
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- OpenShift Container Platform 4.11 update for Golang
- OpenShift Container Platform 4.12 update for Golang
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- OpenShift Container Platform release 4.13 update for golang
- OpenShift Container Platform 4.11 update for golang
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Planning Analytics Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Dell ObjectScale
- Fedora EPEL 8 update for golang-x-net, golang-x-text
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Multiple vulnerabilities in IBM Astronomer with IBM
- IBM Database Operator for FoundationDB update for golang.org/x/text/language