Bug 1190610 - (CVE-2021-37136) VUL-0: CVE-2021-37136: netty: netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data
(CVE-2021-37136)
VUL-0: CVE-2021-37136: netty: netty-codec: Bzip2Decoder doesn't allow setting...
Status: IN_PROGRESS
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/310036/
CVSSv3.1:SUSE:CVE-2021-37136:7.5:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-09-17 13:50 UTC by Gabriele Sonnu
Modified: 2022-11-14 10:58 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gabriele Sonnu 2021-09-17 13:50:21 UTC
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack.

Reference:
https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2004133
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-37136
Comment 1 Gabriele Sonnu 2021-09-17 13:51:31 UTC
Affected packages:

 - SUSE:SLE-15-SP1:Update:Products:Manager40:Update/netty  4.1.8.Final
 - SUSE:SLE-15-SP2:Update:Products:Manager41:Update/netty  4.1.44.Final
 - SUSE:SLE-15-SP3:Update:Products:Manager42:Update/netty  4.1.44.Final
 - openSUSE:Backports:SLE-15-SP2/netty                     4.1.13
 - openSUSE:Backports:SLE-15-SP3/netty                     4.1.13
 - openSUSE:Backports:SLE-15-SP4/netty                     4.1.13
 - openSUSE:Factory/netty                                  4.1.60

Upstream patch:

https://github.com/netty/netty/commit/41d3d61a61608f2223bb364955ab2045dd5e4020
Comment 4 Swamp Workflow Management 2022-04-20 10:27:20 UTC
SUSE-SU-2022:1271-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1182103,1183262,1190610,1190613,1193672
CVE References: CVE-2021-21290,CVE-2021-21295,CVE-2021-37136,CVE-2021-37137,CVE-2021-43797
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    netty-4.1.75-150200.4.6.2
openSUSE Leap 15.3 (src):    netty-4.1.75-150200.4.6.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Thomas Leroy 2022-09-08 12:37:36 UTC
Reassigning to Pedro for SUMA codestreams.

Pedro, could you please ensure that SUSE:SLE-15-SP2:Update:Products:Manager41:Update/netty and SUSE:SLE-15-SP3:Update:Products:Manager42:Update/netty will get the fix for this CVE? :)

Again, if you finally plan to release a new 4.0 version, please include a fix for this bug.
Comment 7 Thomas Leroy 2022-09-08 12:57:10 UTC
(In reply to Thomas Leroy from comment #6)
> Reassigning to Pedro for SUMA codestreams.
> 
> Pedro, could you please ensure that
> SUSE:SLE-15-SP2:Update:Products:Manager41:Update/netty and
> SUSE:SLE-15-SP3:Update:Products:Manager42:Update/netty will get the fix for
> this CVE? :)
> 
> Again, if you finally plan to release a new 4.0 version, please include a
> fix for this bug.

I guess Julio is the correct person. My apologies for the confusion
Comment 11 Swamp Workflow Management 2022-10-18 16:24:56 UTC
SUSE-SU-2022:3617-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1168932,1182103,1190610,1190613
CVE References: CVE-2020-11612,CVE-2021-21290,CVE-2021-37136,CVE-2021-37137
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for SUSE Manager Server 4.2 (src):    netty-4.1.44.Final-150300.4.3.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2022-10-26 14:18:46 UTC
SUSE-SU-2022:3760-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1168932,1182103,1190610,1190613
CVE References: CVE-2020-11612,CVE-2021-21290,CVE-2021-37136,CVE-2021-37137
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for SUSE Manager Server 4.3 (src):    netty-4.1.44.Final-150400.3.3.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2022-10-27 13:24:30 UTC
SUSE-SU-2022:3793-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1168932,1182103,1190610,1190613
CVE References: CVE-2020-11612,CVE-2021-21290,CVE-2021-37136,CVE-2021-37137
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (src):    netty-4.1.44.Final-150200.3.4.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.