Bug 1934852 (CVE-2021-24031)
Summary: | CVE-2021-24031 zstd: adds read permissions to files while being compressed or uncompressed | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sage McTaggart <amctagga> |
Component: | vulnerability | Assignee: | Nobody <nobody> |
Status: | NEW --- | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | anharris, bmontgom, bniver, eparis, flucifre, gmeno, hvyas, jamartis, jburrell, jjoyce, jschluet, kaycoth, lhh, lpeer, mbenjamin, mburns, mhackett, nstielau, p, psegedy, sclewis, slinaber, sostapov, sponnaga, vereddy, vmugicag |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | zstd 1.4.1 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in zstd. While the final file mode is reflective of the input file, when compressing or uncompressing, the file can temporarily gain greater permissions than the input and potentially leading to security issues (especially if large files are being handled).
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2022-12-21 23:30:26 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1935080, 1929435, 1934853, 1934854, 1934855, 1934856, 1935075, 1935076, 1935077, 1935078, 1935079 | ||
Bug Blocks: | 1928095 |
Description
Sage McTaggart
2021-03-03 21:36:11 UTC
Created zstd tracking bugs for this issue: Affects: epel-7 [bug 1934853] Affects: fedora-all [bug 1934854] Affects: openstack-rdo [bug 1934855] Statement: * In OpenShift Container Platform (OCP) the zstd package was delivered in OCP 4.3 which is already end of life. Closing as won't fix. reopening, woops, meant to close a tracker. |