← Back

CVE-2021-20291

nvd nist
Published: Apr 1, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

Affected (5)

Storage
2 products
Enterprise Linux
Openshift Container Platform
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.28.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Version 4.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34

References (12)

Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.