Bug 2011862 (CVE-2021-20319)
| Summary: | CVE-2021-20319 coreos-installer: incorrect signature verification on gzip-compressed install images | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Przemyslaw Roguski <proguski> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | bgilbert, bmontgom, dornelas, dustymabe, eparis, jburrell, jligon, jokerman, jonathan, mrussell, nstielau, rhcos-triage, rust-sig, skunkerk, sponnaga, vkumar |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | coreos-installer 0.10.1 | Doc Type: | If docs needed, set a value |
| Doc Text: |
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-10-26 20:07:59 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2012771, 2012893, 2012894, 2012895, 2012896, 2013108 | ||
| Bug Blocks: | 2008108 | ||
|
Description
Przemyslaw Roguski
2021-10-07 14:46:38 UTC
Created rust-coreos-installer tracking bugs for this issue: Affects: fedora-all [bug 2013108] This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.9 Via RHSA-2021:3934 https://access.redhat.com/errata/RHSA-2021:3934 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-20319 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.8 Via RHSA-2021:3926 https://access.redhat.com/errata/RHSA-2021:3926 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2021:3930 https://access.redhat.com/errata/RHSA-2021:3930 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.6 Via RHSA-2021:4008 https://access.redhat.com/errata/RHSA-2021:4008 |