CVE-2021-3421: Medium severity ibm cloud pak for security vulnerability
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.
Other sources
RPM Project RPM could allow a remote attacker to bypass security restrictions, caused by a flaw in the read function. By persuading a victim to install a seemingly verifiable package or compromise an RPM repository, an attacker could exploit this vulnerability to cause a corruption to the RPM database.
— IBM
The signature header is not signed, but some data is extracted from it and incorporated into the RPM database. It may be possible to insert an erroneous and/or malicious OpenPGP signature into a signed package this way. It is possible to inject strings into the RPM database that the owner of the database would not wish it to contain.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3421?
CVE-2021-3421 is a vulnerability in the RPM package in the read functionality that allows an attacker to cause RPM database corruption.
How does CVE-2021-3421 impact data integrity?
CVE-2021-3421 poses a high threat to data integrity.
Which versions of RPM are affected by CVE-2021-3421?
Versions up to exclusive 4.16.1.3 of RPM are affected by CVE-2021-3421.
How can I fix CVE-2021-3421 on Red Hat Enterprise Linux 8.0?
To fix CVE-2021-3421 on Red Hat Enterprise Linux 8.0, update the RPM package to version 4.17.0 or above.
Where can I find more information about CVE-2021-3421?
You can find more information about CVE-2021-3421 at the following references: [1] [2]