A flaw was found in libhivex. It's possible to provide a large length value for a node which can read past the end of the file leading to read of arbitrary memory and other potential consequences.
Statement: This flaw affects all previous hivex versions up to version 1.3.19
Upstream fix: https://github.com/libguestfs/hivex/commit/8f1935733b10d974a1a4176d38dd151ed98cf381
Created hivex tracking bugs for this issue: Affects: fedora-all [bug 1956204]
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:2318 https://access.redhat.com/errata/RHSA-2021:2318
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:3061 https://access.redhat.com/errata/RHSA-2021:3061