CVE-2021-20319
Summary
| CVE | CVE-2021-20319 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-04 18:15:00 UTC |
| Updated | 2022-03-11 15:37:00 UTC |
| Description | An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| coreos-installer < 0.10.1 improperly verifies GPG signature when decompressing gzipped artifact · Advisory · coreos/coreos-installer · GitHub |
MISC |
github.com |
|
| [release-0.10] io: check for EOF when decoding a gzip stream (CVE-2021-20319) by bgilbert · Pull Request #659 · coreos/coreos-installer · GitHub |
MISC |
github.com |
|
| 2011862 – (CVE-2021-20319) CVE-2021-20319 coreos-installer: incorrect signature verification on gzip-compressed install images |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 239734 Red Hat OpenShift Container Platform 4.9 Security Update (RHSA-2021:3934)
- 239744 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021:3926)
- 239745 Red Hat OpenShift Container Platform 4.7 Security Update (RHSA-2021:3930)
- 239779 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:4008)
- 282001 Fedora Security Update for rust (FEDORA-2021-449a2bdaf3)
- 282002 Fedora Security Update for rust (FEDORA-2021-3d52eb54ca)
- 770084 Red Hat OpenShift Container Platform 4.9 Security Update (RHSA-2021:3934)
- 770085 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021:3926)
- 770086 Red Hat OpenShift Container Platform 4.7 Security Update (RHSA-2021:3930)
- 770087 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:4008)
- 770095 Red Hat OpenShift Container Platform 4.7 Security Update (RHSA-2021-3930)
- 770100 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021-4008)
- 770104 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021-3926)
- 770110 Red Hat OpenShift Container Platform 4.9 Security Update (RHSA-2021-3934)