Bug 1188921 (CVE-2021-37600) - VUL-1: CVE-2021-37600: util-linux: integer overflow can lead to buffer overflow in get_sem_elements() in sys-utils/ipcutils.c
Summary: VUL-1: CVE-2021-37600: util-linux: integer overflow can lead to buffer overfl...
Status: RESOLVED FIXED
Alias: CVE-2021-37600
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Stanislav Brabec
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/305296/
Whiteboard: CVSSv3.1:SUSE:CVE-2021-37600:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2021-07-30 11:26 UTC by Robert Frohl
Modified: 2022-05-16 15:28 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2021-07-30 11:26:10 UTC
rh#1987320

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file.

Reference:
https://github.com/karelzak/util-linux/issues/1395

Upstream patch:
https://github.com/karelzak/util-linux/commit/1c9143d0c1f979c3daf10e1c37b5b1e916c22a1c

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1987320
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-37600
Comment 1 Robert Frohl 2021-07-30 13:23:40 UTC
tracking as affected:

- SUSE:SLE-12-SP2:Update/util-linux
- SUSE:SLE-12-SP3:Update/util-linux
- SUSE:SLE-12-SP4:Update/util-linux
- SUSE:SLE-12-SP5:Update/util-linux
- SUSE:SLE-15:Update/util-linux
- SUSE:SLE-15-SP1:Update/util-linux
- SUSE:SLE-15-SP3:Update/util-linux
Comment 2 Marcus Meissner 2021-09-13 11:27:30 UTC
can you please submit fixed packages to the normal non ltss codestreams?

(12-sp5, 15-sp1, 15-sp3)
Comment 3 Andreas Taschner 2021-09-20 07:20:50 UTC
(In reply to Marcus Meissner from comment #2)
> can you please submit fixed packages to the normal non ltss codestreams?
> 
> (12-sp5, 15-sp1, 15-sp3)

Please excuse my ignorance... but is 15-SP2 not affected or am I missing some basic knowledge about common codestreams ?
Comment 4 Andreas Taschner 2021-09-29 10:19:04 UTC
Would it be possible to get an estimate of when this could start to move ?
Comment 5 Stanislav Brabec 2021-10-01 00:21:34 UTC
Patch applies cleanly for all requested products.

Submitted for SLE15 SP3 and SLE12 SP5.

I will submit the rest as soon as I will fix the testsuite failure for bug 1178236.

Not fixing SLE12 SP1 and older.

https://build.suse.de/project/monitor/home:sbrabec:branches:b1188921-security
Comment 7 Gianluca Gabrielli 2021-10-04 12:40:37 UTC
Hi Stanislav,

we have an issue with the version of the following packages:

 - SUSE:SLE-12-SP5:Update/util-linux 2.33.2
 - SUSE:SLE-15-SP1:Update/util-linux 2.33.1

As you can see SLE-15-SP1 ships a older version than SLE-12-SP5. Usually this is OK since SLE-15-SP1 is actually older than SLE-12-SP5... but in this case it also ships to SLE-15-SP2 products (e.g. SLE-Module-Basesystem_15-SP2) [0].

The actual configuration will break migration from SLE-12-SP5 to SLE-15-SP2, hence needs to be fixed. Do you consider safe upgrading SUSE:SLE-15-SP1:Update/util-linux from 2.33.1 to 2.33.2? If yes, could you submit this update along with the patch mentioned in this ticket?

[0] https://smelt.suse.de/maintained/?q=util-linux
Comment 8 Stanislav Brabec 2021-10-07 04:20:00 UTC
Comment 7: I think it is safe to update SLE15 SP1 to 2.33.2. This is a minor version upgrade. No new tools, the file list is the same.

I did a conservative version upgrade: Upgrade the tarball, make minimal changes in the spec file.

home:sbrabec:branches:b1188921-security/util-linux.SUSE_SLE-15-SP1_Update revision 9 contains just the security, revision 10 includes version upgrade

Submitted with the version upgrade.
Comment 11 Swamp Workflow Management 2021-10-19 13:19:37 UTC
SUSE-SU-2021:3463-1: An update that solves one vulnerability and has 19 fixes is now available.

Category: security (moderate)
Bug References: 1081947,1082293,1084671,1085196,1106214,1122417,1125886,1135534,1135708,1151708,1168235,1168389,1169006,1174942,1175514,1175623,1178236,1178554,1178825,1188921
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    python-libmount-2.29.2-3.24.1, util-linux-2.29.2-3.24.1, util-linux-systemd-2.29.2-3.24.1
SUSE OpenStack Cloud 8 (src):    python-libmount-2.29.2-3.24.1, util-linux-2.29.2-3.24.1, util-linux-systemd-2.29.2-3.24.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    python-libmount-2.29.2-3.24.1, util-linux-2.29.2-3.24.1, util-linux-systemd-2.29.2-3.24.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    python-libmount-2.29.2-3.24.1, util-linux-2.29.2-3.24.1, util-linux-systemd-2.29.2-3.24.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    python-libmount-2.29.2-3.24.1, util-linux-2.29.2-3.24.1, util-linux-systemd-2.29.2-3.24.1
HPE Helion Openstack 8 (src):    python-libmount-2.29.2-3.24.1, util-linux-2.29.2-3.24.1, util-linux-systemd-2.29.2-3.24.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2021-10-20 10:25:58 UTC
openSUSE-SU-2021:3474-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 1178236,1188921
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    python3-libmount-2.36.2-4.5.1, util-linux-2.36.2-4.5.1, util-linux-systemd-2.36.2-4.5.1
Comment 13 Swamp Workflow Management 2021-10-20 10:32:12 UTC
SUSE-SU-2021:3474-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 1178236,1188921
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
SUSE MicroOS 5.1 (src):    util-linux-2.36.2-4.5.1, util-linux-systemd-2.36.2-4.5.1
SUSE Linux Enterprise Module for Server Applications 15-SP3 (src):    util-linux-systemd-2.36.2-4.5.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    util-linux-2.36.2-4.5.1, util-linux-systemd-2.36.2-4.5.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Swamp Workflow Management 2021-10-20 10:35:29 UTC
SUSE-SU-2021:3475-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 1178236,1188921
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP5 (src):    util-linux-2.33.2-4.11.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    util-linux-2.33.2-4.11.1
SUSE Linux Enterprise Server 12-SP5 (src):    python-libmount-2.33.2-4.11.1, util-linux-2.33.2-4.11.1, util-linux-systemd-2.33.2-4.11.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Swamp Workflow Management 2021-10-26 19:22:33 UTC
SUSE-SU-2021:3523-1: An update that solves one vulnerability and has three fixes is now available.

Category: security (moderate)
Bug References: 1122417,1125886,1178236,1188921
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
SUSE MicroOS 5.0 (src):    util-linux-2.33.2-4.16.1, util-linux-systemd-2.33.2-4.16.1
SUSE Linux Enterprise Module for Server Applications 15-SP2 (src):    util-linux-systemd-2.33.2-4.16.1
SUSE Linux Enterprise Module for Basesystem 15-SP2 (src):    util-linux-2.33.2-4.16.1, util-linux-systemd-2.33.2-4.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Swamp Workflow Management 2021-11-02 17:27:45 UTC
openSUSE-SU-2021:1440-1: An update that solves one vulnerability and has three fixes is now available.

Category: security (moderate)
Bug References: 1122417,1125886,1178236,1188921
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    python3-libmount-2.33.2-lp152.5.9.1, util-linux-2.33.2-lp152.5.9.1, util-linux-systemd-2.33.2-lp152.5.9.1
Comment 22 Swamp Workflow Management 2022-04-04 19:19:34 UTC
SUSE-SU-2022:1108-1: An update that solves one vulnerability and has 13 fixes is now available.

Category: security (important)
Bug References: 1084671,1151708,1168235,1168389,1169006,1172427,1174942,1175514,1175623,1178236,1178554,1178825,1188921,1194642
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15 (src):    util-linux-2.31.1-150000.9.18.2, util-linux-systemd-2.31.1-150000.9.18.2
SUSE Linux Enterprise Server 15-LTSS (src):    util-linux-2.31.1-150000.9.18.2, util-linux-systemd-2.31.1-150000.9.18.2
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    util-linux-2.31.1-150000.9.18.2, util-linux-systemd-2.31.1-150000.9.18.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    util-linux-2.31.1-150000.9.18.2, util-linux-systemd-2.31.1-150000.9.18.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Swamp Workflow Management 2022-04-04 19:22:36 UTC
SUSE-SU-2022:1103-1: An update that solves one vulnerability and has 23 fixes is now available.

Category: security (important)
Bug References: 1038841,1081947,1082293,1084671,1085196,1106214,1116347,1122417,1125886,1135534,1135708,1151708,1168235,1168389,1169006,1172427,1174942,1175514,1175623,1178236,1178554,1178825,1188921,1194642
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP2-BCL (src):    python-libmount-2.28-44.35.1, util-linux-2.28-44.35.1, util-linux-systemd-2.28-44.35.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 24 Swamp Workflow Management 2022-04-04 19:25:39 UTC
SUSE-SU-2022:1105-1: An update that solves one vulnerability and has 21 fixes is now available.

Category: security (important)
Bug References: 1081947,1082293,1084671,1085196,1106214,1122417,1125886,1135534,1135708,1151708,1168235,1168389,1169006,1172427,1174942,1175514,1175623,1178236,1178554,1178825,1188921,1194642
CVE References: CVE-2021-37600
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    python-libmount-2.29.2-9.17.1, util-linux-2.29.2-9.17.1, util-linux-systemd-2.29.2-9.17.1
SUSE OpenStack Cloud 9 (src):    python-libmount-2.29.2-9.17.1, util-linux-2.29.2-9.17.1, util-linux-systemd-2.29.2-9.17.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    python-libmount-2.29.2-9.17.1, util-linux-2.29.2-9.17.1, util-linux-systemd-2.29.2-9.17.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    python-libmount-2.29.2-9.17.1, util-linux-2.29.2-9.17.1, util-linux-systemd-2.29.2-9.17.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 25 Stanislav Brabec 2022-05-16 15:28:54 UTC
The fix is released. I guess we can close this bug.