Bug 1186151 - (CVE-2021-38575) VUL-0: CVE-2021-38575: ovmf: NetworkPkg/IScsiDxe: remotely exploitable buffer overflows
(CVE-2021-38575)
VUL-0: CVE-2021-38575: ovmf: NetworkPkg/IScsiDxe: remotely exploitable buffer...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/284541/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-05-18 02:08 UTC by Gary Ching-Pang Lin
Modified: 2021-09-16 12:38 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 6 Gianluca Gabrielli 2021-05-18 10:04:36 UTC
At first glance I would say that the following packages are all affected, but please provide your feedback here.

- SUSE:SLE-12-SP2:Update/ovmf     2015+git1462940744.321151f
- SUSE:SLE-12-SP3:Update/ovmf     2017+git1492060560.b6d11d7c46
- SUSE:SLE-12-SP4:Update/ovmf     2017+git1510945757.b2662641d5
- SUSE:SLE-15-SP2:Update/ovmf     201911
- SUSE:SLE-15-SP3:Update/ovmf     202008
- SUSE:SLE-15:Update/ovmf         2017+git1510945757.b2662641d5
- openSUSE:Factory/ovmf           202102
Comment 7 Gary Ching-Pang Lin 2021-05-19 00:51:30 UTC
(In reply to Gianluca Gabrielli from comment #6)
> At first glance I would say that the following packages are all affected,
> but please provide your feedback here.
> 
> - SUSE:SLE-12-SP2:Update/ovmf     2015+git1462940744.321151f
> - SUSE:SLE-12-SP3:Update/ovmf     2017+git1492060560.b6d11d7c46
> - SUSE:SLE-12-SP4:Update/ovmf     2017+git1510945757.b2662641d5
> - SUSE:SLE-15-SP2:Update/ovmf     201911
> - SUSE:SLE-15-SP3:Update/ovmf     202008
> - SUSE:SLE-15:Update/ovmf         2017+git1510945757.b2662641d5
> - openSUSE:Factory/ovmf           202102

The affected function was introduced since 2011-08 and never changed afterward, so all ovmf packages we have are affected.
Comment 8 Gianluca Gabrielli 2021-05-19 07:27:32 UTC
Thanks for your confirmation. Do you know if a CVE has been assigned to this vulnerability?
Comment 9 Gary Ching-Pang Lin 2021-05-19 07:41:43 UTC
(In reply to Gianluca Gabrielli from comment #8)
> Thanks for your confirmation. Do you know if a CVE has been assigned to this
> vulnerability?

The upstream bug only mentioned that the CVE is being requested and there is no update till now.
Comment 12 Gary Ching-Pang Lin 2021-06-09 01:42:54 UTC
The fixes and upstream bug went public:
https://edk2.groups.io/g/devel/message/76198

There is still no CVE number even though it's requested in upstream bug...
Comment 14 Gary Ching-Pang Lin 2021-06-10 03:24:57 UTC
Submitted fixes to all affected products.
Comment 15 OBSbugzilla Bot 2021-06-10 03:50:06 UTC
This is an autogenerated message for OBS integration:
This bug (1186151) was mentioned in
https://build.opensuse.org/request/show/898914 Factory / ovmf
Comment 16 Swamp Workflow Management 2021-06-22 16:17:40 UTC
SUSE-SU-2021:2118-1: An update that contains security fixes can now be installed.

Category: security (important)
Bug References: 1186151
CVE References: 
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Server Applications 15-SP3 (src):    ovmf-202008-10.8.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Swamp Workflow Management 2021-06-22 16:26:36 UTC
SUSE-SU-2021:2117-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1177789,1183578,1183579,1186151
CVE References: CVE-2019-14584,CVE-2021-28210,CVE-2021-28211
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP2-BCL (src):    ovmf-2015+git1462940744.321151f-19.23.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Swamp Workflow Management 2021-06-22 16:27:46 UTC
SUSE-SU-2021:2119-1: An update that contains security fixes can now be installed.

Category: security (important)
Bug References: 1186151
CVE References: 
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    ovmf-2017+git1492060560.b6d11d7c46-4.44.1
SUSE OpenStack Cloud 8 (src):    ovmf-2017+git1492060560.b6d11d7c46-4.44.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    ovmf-2017+git1492060560.b6d11d7c46-4.44.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    ovmf-2017+git1492060560.b6d11d7c46-4.44.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    ovmf-2017+git1492060560.b6d11d7c46-4.44.1
HPE Helion Openstack 8 (src):    ovmf-2017+git1492060560.b6d11d7c46-4.44.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 19 Swamp Workflow Management 2021-06-24 13:19:14 UTC
SUSE-SU-2021:2151-1: An update that contains security fixes can now be installed.

Category: security (important)
Bug References: 1186151
CVE References: 
JIRA References: 
Sources used:
SUSE MicroOS 5.0 (src):    ovmf-201911-7.21.1
SUSE Linux Enterprise Module for Server Applications 15-SP2 (src):    ovmf-201911-7.21.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 20 Swamp Workflow Management 2021-06-24 13:34:18 UTC
SUSE-SU-2021:2152-1: An update that contains security fixes can now be installed.

Category: security (important)
Bug References: 1186151
CVE References: 
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    ovmf-2017+git1510945757.b2662641d5-3.38.1
SUSE OpenStack Cloud 9 (src):    ovmf-2017+git1510945757.b2662641d5-3.38.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    ovmf-2017+git1510945757.b2662641d5-3.38.1
SUSE Linux Enterprise Server 12-SP5 (src):    ovmf-2017+git1510945757.b2662641d5-3.38.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    ovmf-2017+git1510945757.b2662641d5-3.38.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 21 Swamp Workflow Management 2021-06-25 10:16:02 UTC
openSUSE-SU-2021:0918-1: An update that contains security fixes can now be installed.

Category: security (important)
Bug References: 1186151
CVE References: 
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    ovmf-201911-lp152.6.17.1
Comment 22 Swamp Workflow Management 2021-06-25 13:16:20 UTC
SUSE-SU-2021:2161-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1183578,1183579,1186151
CVE References: CVE-2021-28210,CVE-2021-28211
JIRA References: 
Sources used:
SUSE Manager Server 4.0 (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Manager Retail Branch Server 4.0 (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Manager Proxy 4.0 (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise Server for SAP 15 (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise Server 15-LTSS (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE Enterprise Storage 6 (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1
SUSE CaaS Platform 4.0 (src):    ovmf-2017+git1510945757.b2662641d5-5.43.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Swamp Workflow Management 2021-07-10 22:59:52 UTC
openSUSE-SU-2021:2118-1: An update that contains security fixes can now be installed.

Category: security (important)
Bug References: 1186151
CVE References: 
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    ovmf-202008-10.8.1