This site requires JavaScript to be enabled to function correctly, please enable it.
 
  
    
    
    
    
    Summary: 
    CVE-2021-36159 libfetch: an out of boundary read while libfetch uses strtol to parse the relevant numbers into address bytes leads to information leak or crash 
   
    
      Product: 
      
          [Other] Security Response
       
Reporter: 
      Sandipan Roy <saroy> 
     
    
    Component: 
    vulnerability Assignee: 
      Nobody <nobody> 
   
    
    
      Status: 
      NEW
        ---
       
QA Contact: 
       
    
      Severity: 
      high
       
Docs Contact: 
       
    
      Priority: 
      high
       
  
        
     
    
    Version: 
    unspecified CC: 
      adudiak, agarcial, aoconnor, asegurap, caswilli, dffrench, gzaronik, jburrell, kaycoth, kshier, ngough, rgodfrey, stcannon, tfister, yguenane
    
    
    Target Milestone: 
    --- Keywords: 
      Security 
   
    
    Target Release: 
    ---   
        
   
    
    Hardware: 
    All   
        
   
    OS: 
    Linux   
        
   
    Whiteboard: 
     
        
        
        
  Fixed In Version: 
  
  
 
  
 
        
        
        
        
  Doc Type: 
  
   
  If docs needed, set a value
 
        
  Doc Text: 
  
   
  
      
 
        
        
        
        
  Story Points: 
  
  
 
  ---
 
        
  Clone Of: 
  
  
 
  
 
        
        
        
        
  Environment: 
  
  
 
  
      
 
        
  Last Closed: 
  
  
 
  
    
 
        
        
        
        
  Type: 
  
  
 
  ---
 
        
  Regression: 
  
  
 
  ---
 
        
        
        
        
  Mount Type: 
  
  
 
  ---
 
        
  Documentation: 
  
  
 
  ---
 
        
        
        
        
  CRM: 
  
  
 
  
 
        
  Verified Versions: 
  
   
  
 
        
        
        
        
  Category: 
  
  
 
  ---
 
        
  oVirt Team: 
  
  
 
  ---
 
        
        
        
        
  RHEL 7.3 requirements from Atomic Host: 
  
  
 
  
 
        
  Cloudforms Team: 
  
  
 
  ---
 
        
        
        
        
  Target Upstream Version: 
  
   
  
 
        
  Embargoed: 
  
  
 
  
 
        
    
    Bug Depends On: 
    
     
  
        
   
    Bug Blocks: 
    2218210