Vulnerability BDU:2021-04260: Information

Description

Уязвимость функции xt_compat_target_from_user() (net/netfilter/x_tables.c) подсистемы netfilter операционных систем Linux, позволяющая нарушителю вызвать отказ в обслуживании или повысить свои привилегии

Severity: HIGH (7.8) Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Published: April 13, 2021
Modified: April 13, 2021
Error type identifier: CWE-787

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
kernel-image-mpsisyphus5.12.4-alt16.8.12-alt1ALT-PU-2021-1833-1272140Fixed
kernel-image-mpp105.12.4-alt16.1.19-alt1ALT-PU-2021-1833-1272140Fixed
kernel-image-mpp95.12.16-alt15.12.16-alt1ALT-PU-2021-3481-1279859Fixed
kernel-image-mpp115.12.4-alt16.8.8-alt1ALT-PU-2021-1833-1272140Fixed
kernel-image-rpi-defsisyphus5.10.36-alt15.15.92-alt2ALT-PU-2021-1862-1272154Fixed
kernel-image-rpi-defp105.10.36-alt15.15.92-alt2ALT-PU-2021-1862-1272154Fixed
kernel-image-rpi-defp95.10.36-alt15.10.81-alt1ALT-PU-2021-1866-1272593Fixed
kernel-image-rpi-defp115.10.36-alt15.15.92-alt2ALT-PU-2021-1862-1272154Fixed
kernel-image-rpi-unsisyphus5.10.35-alt16.6.23-alt1ALT-PU-2021-1776-1271376Fixed
kernel-image-rpi-unp105.10.35-alt16.1.77-alt1ALT-PU-2021-1776-1271376Fixed
kernel-image-rpi-unp95.12.6-alt15.12.17-alt1ALT-PU-2021-1896-1273084Fixed
kernel-image-rpi-unp115.10.35-alt16.6.23-alt1ALT-PU-2021-1776-1271376Fixed
kernel-image-rtsisyphus4.19.189-alt1.rt786.1.92-alt1.rt32ALT-PU-2021-1768-1271271Fixed
kernel-image-rtp104.19.189-alt1.rt785.10.218-alt1.rt110ALT-PU-2021-1768-1271271Fixed
kernel-image-rtp94.19.189-alt1.rt784.19.189-alt1.rt78ALT-PU-2021-3430-1287828Fixed
kernel-image-rtc9f24.19.199-alt1.rt864.19.199-alt2.rt86ALT-PU-2021-2671-1283461Fixed
kernel-image-rtp114.19.189-alt1.rt786.1.90-alt2.rt30ALT-PU-2021-1768-1271271Fixed
kernel-image-std-defsisyphus5.10.32-alt16.1.92-alt1ALT-PU-2021-1706-1270544Fixed
kernel-image-std-defp105.10.32-alt15.10.218-alt1ALT-PU-2021-1706-1270544Fixed
kernel-image-std-defp95.4.115-alt15.4.277-alt1ALT-PU-2021-1763-1270900Fixed
kernel-image-std-defp84.9.267-alt0.M80P.14.9.337-alt0.M80P.1ALT-PU-2021-1681-1270079Fixed
kernel-image-std-defc9f25.10.32-alt0.c9f5.10.214-alt0.c9f.2ALT-PU-2021-1739-1270353Fixed
kernel-image-std-defc74.4.277-alt0.M70C.14.4.277-alt0.M70C.1ALT-PU-2021-3033-1281293Fixed
kernel-image-std-defp115.10.32-alt16.1.91-alt1ALT-PU-2021-1706-1270544Fixed
kernel-image-std-kvmsisyphus5.10.32-alt15.10.176-alt1ALT-PU-2021-1711-1270643Fixed
kernel-image-std-kvmp105.10.32-alt15.10.42-alt1ALT-PU-2021-1711-1270643Fixed
kernel-image-std-kvmp115.10.32-alt15.10.176-alt1ALT-PU-2021-1711-1270643Fixed
kernel-image-un-defsisyphus5.12.0-alt16.6.32-alt1ALT-PU-2021-1983-1271593Fixed
kernel-image-un-defp105.12.0-alt16.1.90-alt1ALT-PU-2021-1983-1271593Fixed
kernel-image-un-defp95.10.32-alt15.10.218-alt1ALT-PU-2021-1720-1270546Fixed
kernel-image-un-defp84.19.188-alt0.M80P.14.19.310-alt0.M80P.1ALT-PU-2021-1680-1270075Fixed
kernel-image-un-defc10f15.12.0-alt16.1.85-alt0.c10f.1ALT-PU-2021-1983-1271593Fixed
kernel-image-un-defc74.9.277-alt0.M70C.14.9.277-alt0.M70C.1ALT-PU-2021-3032-1281292Fixed
kernel-image-un-defp115.12.0-alt16.6.31-alt1ALT-PU-2021-1983-1271593Fixed

References to Advisories, Solutions, and Tools

Vulnerability Status
Подтверждена производителем
Presence of an exploit
Существует
Fix status
Уязвимость устранена
Software Type
Операционная система
Solution
Использование рекомендаций:
Для Linux:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21	
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801d	
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.231
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.188
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.267
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.267
https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.31
https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.15
https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.113

Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/CVE-2021-22555

Для Debian:
Использование рекомендаций производителя: https://security-tracker.debian.org/tracker/CVE-2021-22555

Для ОС Astra Linux:
использование рекомендаций производителя: https://wiki.astralinux.ru/astra-linux-se16-bulletin-20211008SE16

Для ОС Аврора 3.2.1: 
https://cve.omprussia.ru/bb10321 

Для ОС Аврора 3.2.2:
https://cve.omprussia.ru/bb11322

Для ОС Аврора 3.2.3: 
https://cve.omprussia.ru/bb12323

Для РедОС: http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
Sources
http://packetstormsecurity.com/files/163528/Linux-Kernel-Netfilter-Heap-Out-Of-Bounds-Write.html
http://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.html
http://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.html
http://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-Privilege-Escalation.html
http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.html
http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
https://access.redhat.com/security/cve/CVE-2021-22555
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22555
https://cve.omprussia.ru/bb10321
https://cve.omprussia.ru/bb11322
https://cve.omprussia.ru/bb12323
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801d
https://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528
https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.231
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.188
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.267
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.267
https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.31
https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.15
https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.113
https://nvd.nist.gov/vuln/detail/CVE-2021-22555
https://security.netapp.com/advisory/ntap-20210805-0010/
https://ubuntu.com/security/notices/USN-5039-1
https://wiki.astralinux.ru/astra-linux-se16-bulletin-20211008SE16
https://www.cve.org/CVERecord?id=CVE-2021-22555
https://www.opennet.ru/opennews/art.shtml?num=55488
Other system identifiers