Vulnerability Name:

CVE-2021-3326 (CCN-195732)

Assigned:2021-01-27
Published:2021-01-27
Updated:2022-11-04
Summary:The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-617
CWE-617
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-3326

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20210128 Re: glibc iconv crash with ISO-2022-JP-3

Source: XF
Type: UNKNOWN
glibc-cve20213326-dos(195732)

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20221017 [SECURITY] [DLA 3152-1] glibc security update

Source: CCN
Type: oss-sec Mailing List, Wed, 27 Jan 2021 15:16:40 -0000 (UTC)
glibc iconv crash with ISO-2022-JP-3

Source: GENTOO
Type: Third Party Advisory
GLSA-202107-07

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20210304-0007/

Source: CCN
Type: Sourceware Bugzilla - Bug 27256
Assertion failure in ISO-2022-JP-3 gconv module related to combining characters

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://sourceware.org/bugzilla/show_bug.cgi?id=27256

Source: MISC
Type: Patch, Third Party Advisory
https://sourceware.org/git/?p=glibc.git;a=commit;h=7d88c6142c6efc160c0ee5e4f85cde382c072888

Source: CCN
Type: GNU Web site
The GNU C Library (glibc)

Source: CCN
Type: IBM Security Bulletin 6493729 (Cloud Pak for Security)
Cloud Pak for Security is vulnerable to several CVEs

Source: CCN
Type: IBM Security Bulletin 6520474 (QRadar SIEM)
IBM QRadar SIEM Application Framework Base Image is vulnerable to using components with Known Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6526502 (App Connect Professional)
App Connect Professional is affected by GNU C Library vulnerability

Source: CCN
Type: IBM Security Bulletin 6538418 (Security Verify Access)
Multiple Security Vulnerabilities fixed in IBM Security Verify Access

Source: CCN
Type: IBM Security Bulletin 6982841 (Netcool Operations Insight)
Netcool Operations Insight v1.6.8 addresses multiple security vulnerabilities.

Source: MISC
Type: Not Applicable
https://www.oracle.com/security-alerts/cpuapr2022.html

Source: CCN
Type: Oracle CPUJan2022
Oracle Critical Patch Update Advisory - January 2022

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-3326

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:glibc:*:*:*:*:*:*:*:* (Version <= 2.32.0)

  • Configuration 2:
  • cpe:/a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:* (Version >= 11.0 and <= 11.60.3)

  • Configuration 3:
  • cpe:/a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.5.0:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:* (Version < xcp2410)
  • AND
  • cpe:/h:fujitsu:m10-1:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:* (Version < xcp2410)
  • AND
  • cpe:/h:fujitsu:m10-4:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:* (Version < xcp2410)
  • AND
  • cpe:/h:fujitsu:m10-4s:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:* (Version < xcp2410)
  • AND
  • cpe:/h:fujitsu:m12-1:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:* (Version < xcp2410)
  • AND
  • cpe:/h:fujitsu:m12-2:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:* (Version < xcp2410)
  • AND
  • cpe:/h:fujitsu:m12-2:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:* (Version < xcp2410)
  • AND
  • cpe:/h:fujitsu:m12-2s:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:* (Version < xcp3110)
  • AND
  • cpe:/h:fujitsu:m10-1:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:* (Version < xcp3110)
  • AND
  • cpe:/h:fujitsu:m10-4:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:* (Version < xcp3110)
  • AND
  • cpe:/h:fujitsu:m10-4s:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:* (Version < xcp3110)
  • AND
  • cpe:/h:fujitsu:m12-1:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:* (Version < xcp3110)
  • AND
  • cpe:/h:fujitsu:m12-2:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:* (Version < xcp3110)
  • AND
  • cpe:/h:fujitsu:m12-2:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:* (Version < xcp3110)
  • AND
  • cpe:/h:fujitsu:m12-2s:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnu:glibc:2.32:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:qradar_security_information_and_event_manager:7.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_verify_access:10.0.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_verify_access:10.0.1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8010
    P
    glibc-devel-32bit-2.31-150300.46.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7510
    P
    glibc-2.31-150300.46.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:93158
    P
    (Important)
    2022-07-14
    oval:org.opensuse.security:def:93311
    P
    (Important)
    2022-07-08
    oval:org.opensuse.security:def:3568
    P
    libXv1-1.0.10-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3385
    P
    tpm2.0-tools-3.1.4-1.12 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94565
    P
    glibc-2.31-150300.20.7 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94680
    P
    libp11-kit0-0.23.22-150400.1.10 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95015
    P
    glibc-devel-32bit-2.31-150300.20.7 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2935
    P
    glibc-2.31-150300.20.7 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94946
    P
    libical-devel-3.0.10-150400.1.8 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:68
    P
    glibc-2.31-7.30 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:101659
    P
    Security update for python-libxml2-python (Important)
    2022-03-10
    oval:org.opensuse.security:def:99203
    P
    (Important)
    2022-01-25
    oval:org.opensuse.security:def:112305
    P
    glibc-2.34-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:997
    P
    Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-operator-container (Important)
    2022-01-10
    oval:org.opensuse.security:def:4537
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP5) (Important)
    2021-12-14
    oval:org.opensuse.security:def:102214
    P
    Security update for util-linux (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:105828
    P
    glibc-2.34-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:101393
    P
    python3-virt-bootstrap-1.0.0-5.3.124 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:1919
    P
    glibc-devel-32bit-2.31-7.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62086
    P
    glibc-2.31-7.30 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63008
    P
    glibc-devel-32bit-2.31-7.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71827
    P
    glibc-2.31-7.30 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100844
    P
    glibc-2.31-7.30 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72727
    P
    glibc-devel-32bit-2.31-7.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101266
    P
    glibc-devel-32bit-2.31-7.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:99398
    P
    (Moderate)
    2021-07-20
    oval:com.redhat.rhsa:def:20211585
    P
    RHSA-2021:1585: glibc security, bug fix, and enhancement update (Moderate)
    2021-05-18
    oval:org.opensuse.security:def:111242
    P
    Security update for glibc (Important)
    2021-02-27
    oval:org.opensuse.security:def:10208
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:99597
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:5953
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:108880
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:92058
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:65626
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:73779
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:9454
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:99008
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:92846
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:69987
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:117839
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:10398
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:99796
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:8707
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:92253
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:97247
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:67042
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:74694
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:9648
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:93005
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:108059
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:70348
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:100108
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:8897
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:92448
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:69594
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:76110
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:9847
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:108325
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:70538
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:64657
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:9092
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:95501
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:92647
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:69788
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:117573
    P
    Security update for glibc (Important)
    2021-02-26
    oval:org.opensuse.security:def:26200
    P
    Security update for glibc (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:34639
    P
    Security update for glibc (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:5187
    P
    Security update for glibc (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:60462
    P
    Security update for glibc (Moderate)
    2021-02-25
    BACK
    gnu glibc *
    netapp ontap select deploy administration utility -
    netapp e-series santricity os controller *
    oracle communications cloud native core security edge protection proxy 1.5.0
    fujitsu m10-1 firmware *
    fujitsu m10-1 -
    fujitsu m10-4 firmware *
    fujitsu m10-4 -
    fujitsu m10-4s firmware *
    fujitsu m10-4s -
    fujitsu m12-1 firmware *
    fujitsu m12-1 -
    fujitsu m12-2 firmware *
    fujitsu m12-2 -
    fujitsu m12-2 firmware *
    fujitsu m12-2 -
    fujitsu m12-2s firmware *
    fujitsu m12-2s -
    fujitsu m10-1 firmware *
    fujitsu m10-1 -
    fujitsu m10-4 firmware *
    fujitsu m10-4 -
    fujitsu m10-4s firmware *
    fujitsu m10-4s -
    fujitsu m12-1 firmware *
    fujitsu m12-1 -
    fujitsu m12-2 firmware *
    fujitsu m12-2 -
    fujitsu m12-2 firmware *
    fujitsu m12-2 -
    fujitsu m12-2s firmware *
    fujitsu m12-2s -
    debian debian linux 10.0
    gnu glibc 2.32
    ibm qradar security information and event manager 7.3
    ibm qradar security information and event manager 7.4 -
    ibm security verify access 10.0.0
    ibm security verify access 10.0.2.0
    ibm cloud pak for security 1.7.0.0
    ibm cloud pak for security 1.7.1.0
    ibm cloud pak for security 1.7.2.0
    ibm security verify access 10.0.1.0