libsolv: heap-overflows in resolve_dependencies function
Published Feb 21, 2022
6.5
MEDIUMCVSS 3.1
EPSS 1.79%
Description
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.
Affected products
No data.
No data.
Red Hat Satellite 6.11 for RHEL 7
libsolv-0:0.7.22-1.el7pc
Fixed · RHSA-2022:5498
Red Hat Satellite 6.11 for RHEL 7
libsolv-0:0.7.22-1.el7pc
Fixed · RHSA-2022:5498
Red Hat Satellite 6.11 for RHEL 8
libsolv-0:0.7.22-1.el8pc
Fixed · RHSA-2022:5498
Red Hat Satellite 6.11 for RHEL 8
libsolv-0:0.7.22-1.el8pc
Fixed · RHSA-2022:5498
Red Hat Enterprise Linux 7
libsolv
Out of support scope
Red Hat Enterprise Linux 8
libsolv
Not affected
Red Hat Enterprise Linux 9
libsolv
Not affected
Red Hat Update Infrastructure 3 for Cloud Providers
libsolv
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.11 for RHEL 7 | libsolv-0:0.7.22-1.el7pc | Fixed | RHSA-2022:5498 |
| Red Hat Satellite 6.11 for RHEL 7 | libsolv-0:0.7.22-1.el7pc | Fixed | RHSA-2022:5498 |
| Red Hat Satellite 6.11 for RHEL 8 | libsolv-0:0.7.22-1.el8pc | Fixed | RHSA-2022:5498 |
| Red Hat Satellite 6.11 for RHEL 8 | libsolv-0:0.7.22-1.el8pc | Fixed | RHSA-2022:5498 |
| Red Hat Enterprise Linux 7 | libsolv | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | libsolv | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libsolv | Not affected | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | libsolv | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw has been marked as Low impact because it is in the test case reader and is an out-of-bounds read. This issue is related to already fixed issue (https://github.com/openSUSE/libsolv/commit/0077ef29eb46d2e1df2f230fc95a1d9748d49dec) that is part of libsolv-0.7.17. RHEL-8.6.z and above, and RHEL-9 ships versions of libsolv greater than 0.7.17. Hence, as the flaw is having LOW security impact, Red Hat Enterprise Linux - 8, 9 are set to not affected. However, RHEL-8 streams that ships libsolv versions prior to 0.7.17 are still affected. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/.
References (8)
- https://access.redhat.com/security/cve/CVE-2021-44568 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2057178 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-31392 Advisory
- https://github.com/openSUSE/libsolv/issues/425 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1940 x_refsource_MISCExploitThird Party Advisory
- https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1995 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-44568
- https://www.cve.org/CVERecord?id=CVE-2021-44568
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-44568 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2057178 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-31392 | Advisory | |
| https://github.com/openSUSE/libsolv/issues/425 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1940 | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1995 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-44568 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-44568 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data