Vulnerability Name:

CVE-2021-3622 (CCN-216211)

Assigned:2021-08-02
Published:2021-08-02
Updated:2022-01-10
Summary:A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
CVSS v3 Severity:4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
4.3 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
3.8 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-400
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-3622

Source: CCN
Type: Red Hat Bugzilla - Bug 1975489
(CVE-2021-3622) - CVE-2021-3622 hivex: stack overflow due to recursive call of _get_children()

Source: MISC
Type: Exploit, Issue Tracking, Patch, Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1975489

Source: XF
Type: UNKNOWN
hivex-cve20213622-dos(216211)

Source: CCN
Type: hivex GIT Repository
lib/node.c: Limit recursion in ri-records (CVE-2021-3622)

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/libguestfs/hivex/commit/771728218dac2fbf6997a7e53225e75a4c6b7255

Source: MISC
Type: Mailing List, Patch, Vendor Advisory
https://listman.redhat.com/archives/libguestfs/2021-August/msg00002.html

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-775b170f95

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-372d83d54e

Source: CCN
Type: Mend Vulnerability Database
CVE-2021-3622

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:hivex:*:*:*:*:*:*:*:* (Version < 1.3.21)

  • Configuration 2:
  • cpe:/o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:34:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8046
    P
    ocaml-hivex-1.3.21-150400.2.10 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7527
    P
    hivex-devel-1.3.21-150400.2.10 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:779
    P
    Security update for MozillaFirefox (Important)
    2022-09-26
    oval:org.opensuse.security:def:3680
    P
    Security update for MozillaFirefox (Important)
    2022-07-06
    oval:org.opensuse.security:def:3489
    P
    fontconfig-2.11.1-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3411
    P
    yast2-3.2.50-4.7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94914
    P
    gvim-8.0.1568-5.17.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2949
    P
    hivex-devel-1.3.21-150400.2.10 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94579
    P
    hivex-devel-1.3.21-150400.2.10 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95041
    P
    ocaml-hivex-1.3.21-150400.2.10 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94601
    P
    libQt5Concurrent-devel-5.15.2+kde294-150400.4.8 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95390
    P
    Security update for redis (Moderate)
    2022-06-02
    oval:com.redhat.rhsa:def:20221759
    P
    RHSA-2022:1759: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
    2022-05-10
    oval:org.opensuse.security:def:4575
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 12 SP5) (Important)
    2022-04-15
    oval:org.opensuse.security:def:102103
    P
    Security update for php7 (Important)
    2022-03-15
    oval:org.opensuse.security:def:6181
    P
    Security update for java-11-openjdk (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:101627
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:112401
    P
    hivex-1.3.21-2.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:4505
    P
    Security update for the Linux Kernel (Live Patch 11 for SLE 12 SP5) (Important)
    2021-10-14
    oval:org.opensuse.security:def:42221
    P
    Security update for hivex (Moderate)
    2021-10-04
    oval:org.opensuse.security:def:105910
    P
    hivex-1.3.21-2.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:111073
    P
    Security update for hivex (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:75999
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:108769
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:101802
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:64578
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:73891
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:117494
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:66931
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:76338
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:5842
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:26135
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:64769
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:74662
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:117807
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:107980
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:67270
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:58834
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:33011
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:87475
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:65594
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:74732
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:42123
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:108293
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:101510
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:60371
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:73700
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:5122
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:34548
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:1124
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:111724
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:101314
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:65664
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:com.redhat.rhsa:def:20213338
    P
    RHSA-2021:3338: hivex security update (Low)
    2021-08-31
    BACK
    redhat hivex *
    redhat enterprise linux 6.0
    redhat enterprise linux 7.0
    redhat enterprise linux 8.0
    redhat enterprise linux 8.0
    redhat enterprise linux workstation 7.0
    fedoraproject fedora 33
    fedoraproject fedora 34