CVE-2021-21404
Summary
| CVE | CVE-2021-21404 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-06 20:15:00 UTC |
| Updated | 2021-04-14 18:00:00 UTC |
| Description | Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv` can be caused to crash and exit by sending a relay message with a negative length field. Similarly, Syncthing itself can crash for the same reason if given a malformed message from a malicious relay server when attempting to join the relay. Relay joins are essentially random (from a subset of low latency relays) and Syncthing will by default restart when crashing, at which point it's likely to pick another non-malicious relay. This flaw is fixed in version 1.15.0. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v1.15.0 · syncthing/syncthing · GitHub | MISC | github.com | |
| syncthing · pkg.go.dev | MISC | pkg.go.dev | |
| Merge pull request from GHSA-x462-89pf-6r5h · syncthing/syncthing@fb4fdaf · GitHub | MISC | github.com | |
| Crash due to malformed relay protocol message · Advisory · syncthing/syncthing · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180256 Debian Security Update for syncthing (CVE-2021-21404)
- 501696 Alpine Linux Security Update for syncthing
- 501928 Alpine Linux Security Update for syncthing
- 690173 Free Berkeley Software Distribution (FreeBSD) Security Update for syncthing (9ee01e60-6045-43df-98e5-a794007e54ef)
- 750224 OpenSUSE Security Update for syncthing (openSUSE-SU-2021:0688-1)
- 982429 Go (go) Security Update for github.com/syncthing/syncthing (GHSA-x462-89pf-6r5h)