RHSA-2021:4060: Moderate: libsolv security update
The libsolv packages provide a library for resolving package dependencies using a satisfiability algorithm.Security Fix(es): libsolv: heap-based buffer overflow in poolinstallable() in src/repo.h (CVE-2021-33928) libsolv: heap-based buffer overflow in pooldisabledsolvable() in src/repo.h (CVE-2021-33929) libsolv: heap-based buffer overflow in poolinstallablewhatprovides() in src/repo.h (CVE-2021-33930) libsolv: heap-based buffer overflow in prunetorecommended() in src/policy.c (CVE-2021-33938) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libsolvto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/libsolv-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/libsolv-debugsourceto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/libsolv-demo-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/libsolv-tools-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/perl-solv-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/python3-solvto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/python3-solv-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/ruby-solv-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/libsolvto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/libsolv-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/libsolv-debugsourceto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/libsolv-demo-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/libsolv-tools-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/perl-solv-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/python3-solvto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/python3-solv-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/ruby-solv-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/libsolv-develto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/libsolv-toolsto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4 - Upgrade
Upgrade
redhat/libsolv-develto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa - Upgrade
Upgrade
redhat/libsolv-toolsto a version that resolves this vulnerability.Fixed in 0.7.16-3.el8_4.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:4060?
The severity of RHSA-2021:4060 is classified as important due to the presence of a heap-based buffer overflow vulnerability.
How do I fix RHSA-2021:4060?
To fix RHSA-2021:4060, update the libsolv package to version 0.7.16-3.el8_4 or later.
What are the affected packages in RHSA-2021:4060?
The affected packages in RHSA-2021:4060 include libsolv, libsolv-debuginfo, and libsolv-tools among others.
What is CVE-2021-33928 linked to RHSA-2021:4060?
CVE-2021-33928 is a vulnerability that describes a heap-based buffer overflow in the pool_installable() function in libsolv.
Is my system vulnerable if I have an outdated version of libsolv?
Yes, if you have an outdated version of libsolv prior to 0.7.16-3.el8_4, your system is vulnerable to exploitation via CVE-2021-33928.