Bug 2006950 (CVE-2020-21913)

Summary: CVE-2020-21913 icu: Use after free in pkg_createWithAssemblyCode function in tools/pkgdata/pkgdata.cpp
Product: [Other] Security Response Reporter: Pedro Sampaio <psampaio>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ahughes, aileenc, aos-bugs, bdettelb, bmontgom, caillon+fedoraproject, caswilli, chazlett, dbhole, denis.arnaud_fedora, drieden, eng-i18n-bugs, eparis, erack, erik-fedora, fnasser, ggaughan, gmalinko, hhorak, janstey, java-sig-commits, jburrell, jkang, jochrist, jorton, jvanek, jwon, kaycoth, krzysztof.daniel, lef, loganjerry, manisandro, mcatanza, mfabian, mizdebsk, mrunge, neugens, nodejs-maint, nodejs-sig, nsantos, nstielau, patrickm, petersen, pjindal, psegedy, rh-spice-bugs, rhughes, rstrode, sandmann, sd-operator-metering, sgallagh, sponnaga, tchollingsworth, tflannag, thrcka, tpopela, tuxator, vmugicag, walter.pete, zsvetlik
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: icu 66.1 Doc Type: If docs needed, set a value
Doc Text:
A use after free flaw was discovered in the International Components for Unicode (icu) file tools package pkgdata. The highest threat from this vulnerability is to system availability.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-04-04 13:14:39 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2010314, 2010315    
Bug Blocks: 2006957    

Description Pedro Sampaio 2021-09-22 17:47:08 UTC
International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.

References:

https://github.com/unicode-org/icu/pull/886
https://unicode-org.atlassian.net/browse/ICU-20850