CVE-2021-20291
published 2021-04-01CVE-2021-20291: A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.59%
72.9th percentile
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| containers | storage | — | — |
| debian | golang-github-containers-storage | < golang-github-containers-storage 1.34.1+ds1-1 (bookworm) | golang-github-containers-storage 1.34.1+ds1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | containers_storage | >= 0 < 1.28.1 | 1.28.1 |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| storage_project | storage | < 1.28.1 | 1.28.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Denial of service via deadlock in github.com/containers/storage
osv·2021-07-28
CVE-2021-20291 Denial of service via deadlock in github.com/containers/storage
Denial of service via deadlock in github.com/containers/storage
Due to a goroutine deadlock, using github.com/containers/storage/pkg/archive.DecompressStream on a xz archive returns a reader which will hang indefinitely when Close is called. An attacker can use this to cause denial of service if they are able to cause the caller to attempt to decompress an archive they control.
GHSA
Improper Locking in github.com/containers/storage
ghsa·2021-05-10
CVE-2021-20291 [MEDIUM] CWE-400 Improper Locking in github.com/containers/storage
Improper Locking in github.com/containers/storage
A deadlock vulnerability was found in `github.com/containers/storage` in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).
OSV
Improper Locking in github.com/containers/storage
osv·2021-05-10
CVE-2021-20291 [MEDIUM] Improper Locking in github.com/containers/storage
Improper Locking in github.com/containers/storage
A deadlock vulnerability was found in `github.com/containers/storage` in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).
OSV
CVE-2021-20291: A deadlock vulnerability was found in 'github
osv·2021-04-01·CVSS 6.5
CVE-2021-20291 [MEDIUM] CVE-2021-20291: A deadlock vulnerability was found in 'github
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).
Red Hat
containers/storage: DoS via malicious image
vendor_redhat·2021-04-01·CVSS 6.5
CVE-2021-20291 [MEDIUM] CWE-667 containers/storage: DoS via malicious image
containers/storage: DoS via malicious image
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).
A deadlock vulnerability was found in `github.com/containers/storage`. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a val
Debian
CVE-2021-20291: golang-github-containers-storage - A deadlock vulnerability was found in 'github.com/containers/storage' in version...
vendor_debian·2021·CVSS 6.5
CVE-2021-20291 [MEDIUM] CVE-2021-20291: golang-github-containers-storage - A deadlock vulnerability was found in 'github.com/containers/storage' in version...
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).
Scope: local
bookworm: resolved (fixed in 1.34.1+ds1-1)
bullseye: open
forky: resolved (fixed in 1.34.1+ds1-1)
sid: resolved (fixed in 1.34.1+ds1-1)
trixie: resolved (fixed in 1.34.1+ds1-1)
No detection rules found.
No public exploits indexed.
Unit42
New Vulnerability Affecting Container Engines CRI-O and Podman (CVE-2021-20291)
blogs_unit42·2021-04-14·CVSS 6.5
CVE-2021-20291 [MEDIUM] New Vulnerability Affecting Container Engines CRI-O and Podman (CVE-2021-20291)
Threat Research Center
Threat Research
Vulnerabilities
## New Vulnerability Affecting Container Engines CRI-O and Podman (CVE-2021-20291)
Aviv Sasson
Published: April 14, 2021
Threat Research
Vulnerabilities
Containers
CRI-O
CVE-2021-20291
Kubernetes
Podman LXC Container Security
## Executive Summary
As part of our initiative to improve security in the cloud-native landscape, I conducted a security audit of multiple Go libraries that Kubernetes is based on. In my research, I found CVE-2021-20291 in containers/storage that leads to a Denial of Service (DoS) of the container engines CRI-O and Podman when pulling a malicious image from a registry. Through this vulnerability, malicious actors could jeopardize any containerized infrastructure that relies on these vulnerable co
Unit42
New Vulnerability Affecting Container Engines CRI-O and Podman (CVE-2021-20291)
blogs_unit42·2021-04-14·CVSS 6.5
CVE-2021-20291 [MEDIUM] New Vulnerability Affecting Container Engines CRI-O and Podman (CVE-2021-20291)
## Executive Summary
As part of our initiative to improve security in the cloud-native landscape, I conducted a security audit of multiple Go libraries that Kubernetes is based on. In my research, I found CVE-2021-20291 in containers/storage that leads to a Denial of Service (DoS) of the container engines CRI-O and Podman when pulling a malicious image from a registry. Through this vulnerability, malicious actors could jeopardize any containerized infrastructure that relies on these vulnerable container engines, including Kubernetes and OpenShift.
Palo Alto Networks customers running Prisma Cloud are protected from this vulnerability through the Prisma Cloud Compute host vulnerability scanner and the Trusted Images feature.
## Disclosure Process
We responsibly disclosed the vulnerabili
https://bugzilla.redhat.com/show_bug.cgi?id=1939485https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5D7XL7FL24TWFMGQ3K2S72EOUSLZMKL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYOHNG2Q7DCAQZMGYLMENLKALGDLG3X/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WX24EITRXVHDM5M223BVTJA2ODF2FSHI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNMB7O2UIXE34PGSCSOULGHPX5LIJBMM/https://unit42.paloaltonetworks.com/cve-2021-20291/https://bugzilla.redhat.com/show_bug.cgi?id=1939485https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5D7XL7FL24TWFMGQ3K2S72EOUSLZMKL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYOHNG2Q7DCAQZMGYLMENLKALGDLG3X/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WX24EITRXVHDM5M223BVTJA2ODF2FSHI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNMB7O2UIXE34PGSCSOULGHPX5LIJBMM/https://unit42.paloaltonetworks.com/cve-2021-20291/
2021-04-01
Published