CVE-2021-20291
Summary
| CVE | CVE-2021-20291 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-01 18:15:00 UTC |
| Updated | 2023-11-07 03:29:00 UTC |
| Description | A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: runc-1.0.0-377.rc93.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 1939485 – (CVE-2021-20291) CVE-2021-20291 containers/storage: DoS via malicious image |
MISC |
bugzilla.redhat.com |
|
| [SECURITY] Fedora 33 Update: skopeo-1.2.3-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: skopeo-1.2.3-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| New Vulnerability Affecting Container Engines CRI-O and Podman (CVE-2021-20291) |
MISC |
unit42.paloaltonetworks.com |
|
| [SECURITY] Fedora 33 Update: buildah-1.20.1-4.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: skopeo-1.2.3-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: skopeo-1.2.3-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: runc-1.0.0-377.rc93.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: buildah-1.20.1-4.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159464 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2021-4154)
- 160277 Oracle Enterprise Linux Security Update for skopeo (ELSA-2022-7955)
- 160285 Oracle Enterprise Linux Security Update for buildah (ELSA-2022-8008)
- 160293 Oracle Enterprise Linux Security Update for podman (ELSA-2022-7954)
- 182468 Debian Security Update for golang-github-containers-storage (CVE-2021-20291)
- 239248 Red Hat Update for OpenShift Container Platform 4.7.7 (RHSA-2021:1150)
- 239825 Red Hat Update for container-tools:rhel8 security (RHSA-2021:4154)
- 240876 Red Hat Update for podman (RHSA-2022:7954)
- 240894 Red Hat Update for buildah (RHSA-2022:8008)
- 240920 Red Hat Update for skopeo (RHSA-2022:7955)
- 281086 Fedora Security Update for buildah, containers-common (FEDORA-2021-ec00da7faa)
- 281292 Fedora Security Update for buildah (FEDORA-2021-ec00da7faa)
- 281300 Fedora Security Update for buildah (FEDORA-2021-83b3740389)
- 281302 Fedora Security Update for skopeo (FEDORA-2021-c56a213327)
- 281303 Fedora Security Update for skopeo (FEDORA-2021-a3703b9dc8)
- 751822 OpenSUSE Security Update for conmon, libcontainers-common, libseccomp, podman (openSUSE-SU-2022:23018-1)
- 752014 SUSE Enterprise Linux Security Update for conmon, libcontainers-common, libseccomp, podman (SUSE-SU-2022:23018-1)
- 752601 SUSE Enterprise Linux Security Update for libcontainers-common (SUSE-SU-2022:3312-1)
- 770057 Red Hat OpenShift Container Platform 4.7.7 Security Update (RHSA-2021:1150)
- 770088 Red Hat OpenShift Container Platform 4.7 Security Update (RHSA-2021-1150)
- 940445 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2021:4154)
- 940827 AlmaLinux Security Update for buildah (ALSA-2022:8008)
- 940833 AlmaLinux Security Update for skopeo (ALSA-2022:7955)
- 940834 AlmaLinux Security Update for podman (ALSA-2022:7954)
- 960213 Rocky Linux Security Update for container-tools:rhel8 (RLSA-2021:4154)
- 982395 Go (go) Security Update for github.com/containers/storage/pkg/archive (GHSA-7qw8-847f-pggm)