CVE-2021-21419
published 2021-05-07CVE-2021-21419: Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.81%
76.1th percentile
Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame. A patch in version 0.31.0 restricts websocket frame to reasonable limits. As a workaround, restricting memory usage via OS limits would help against overall machine exhaustion, but there is no workaround to protect Eventlet process.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-eventlet | < python-eventlet 0.26.1-7 (bookworm) | python-eventlet 0.26.1-7 (bookworm) |
| debian | python-eventlet | — | — |
| eventlet | eventlet | >= 0.10 < 0.31.0 | 0.31.0 |
| eventlet | eventlet | >= 0.10 < 0.31.0 | 0.31.0 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-326p-894x-j8c7: A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-20
ghsa_unreviewed·2023-11-01·CVSS 5.3
CVE-2023-5625 [MEDIUM] CWE-400 GHSA-326p-894x-j8c7: A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-20
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
GHSA
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
ghsa·2021-05-07
CVE-2021-21419 [MEDIUM] CWE-400 Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
### Impact
A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame.
### Patches
Version 0.31.0 restricts websocket frame to reasonable limits.
### Workarounds
Restricting memory usage via OS limits would help against overall machine exhaustion. No workaround to protect Eventlet process.
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [eventlet](https://github.com/eventlet/eventlet/issues)
* Contact current maintainers. At 2021-03: [email protected] or https://t.me/temotor
OSV
CVE-2021-21419: Eventlet is a concurrent networking library for Python
osv·2021-05-07·CVSS 5.3
CVE-2021-21419 [MEDIUM] CVE-2021-21419: Eventlet is a concurrent networking library for Python
Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame. A patch in version 0.31.0 restricts websocket frame to reasonable limits. As a workaround, restricting memory usage via OS limits would help against overall machine exhaustion, but there is no workaround to protect Eventlet process.
OSV
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
osv·2021-05-07
CVE-2021-21419 [MEDIUM] Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
### Impact
A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame.
### Patches
Version 0.31.0 restricts websocket frame to reasonable limits.
### Workarounds
Restricting memory usage via OS limits would help against overall machine exhaustion. No workaround to protect Eventlet process.
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [eventlet](https://github.com/eventlet/eventlet/issues)
* Contact current maintainers. At 2021-03: [email protected] or https://t.me/temotor
Red Hat
python-eventlet: patch regression for CVE-2021-21419 in some Red Hat builds
vendor_redhat·2023-10-17·CVSS 5.3
CVE-2023-5625 [MEDIUM] CWE-770 python-eventlet: patch regression for CVE-2021-21419 in some Red Hat builds
python-eventlet: patch regression for CVE-2021-21419 in some Red Hat builds
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
Debian
CVE-2023-5625: python-eventlet - A regression was introduced in the Red Hat build of python-eventlet due to a cha...
vendor_debian·2023·CVSS 5.3
CVE-2023-5625 [MEDIUM] CVE-2023-5625: python-eventlet - A regression was introduced in the Red Hat build of python-eventlet due to a cha...
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Ubuntu
Eventlet vulnerability
vendor_ubuntu·2021-05-17
CVE-2021-21419 Eventlet vulnerability
Title: Eventlet vulnerability
Summary: Eventlet could be made denial of service if it received a specially
crafted request.
It was discovered that Eventlet incorrectly handled certain requests.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-eventlet: improper handling of highly compressed data and memory allocation with excessive size allows DoS
vendor_redhat·2021-05-06·CVSS 5.3
CVE-2021-21419 [MEDIUM] CWE-400 python-eventlet: improper handling of highly compressed data and memory allocation with excessive size allows DoS
python-eventlet: improper handling of highly compressed data and memory allocation with excessive size allows DoS
Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame. A patch in version 0.31.0 restricts websocket frame to reasonable limits. As a workaround, restricting memory usage via OS limits would help against overall machine exhaustion, but there is no workaround to protect Eventlet process.
A flaw was found in eventlet. If an unauthenticated user manages to send large websocket frames or highly compressed data frames that can lead to memory exhaustion. An attacker could use this flaw to cause a de
Debian
CVE-2021-21419: python-eventlet - Eventlet is a concurrent networking library for Python. A websocket peer may exh...
vendor_debian·2021·CVSS 5.3
CVE-2021-21419 [MEDIUM] CVE-2021-21419: python-eventlet - Eventlet is a concurrent networking library for Python. A websocket peer may exh...
Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame. A patch in version 0.31.0 restricts websocket frame to reasonable limits. As a workaround, restricting memory usage via OS limits would help against overall machine exhaustion, but there is no workaround to protect Eventlet process.
Scope: local
bookworm: resolved (fixed in 0.26.1-7)
bullseye: resolved (fixed in 0.26.1-7)
forky: resolved (fixed in 0.26.1-7)
sid: resolved (fixed in 0.26.1-7)
trixie: resolved (fixed in 0.26.1-7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/eventlet/eventlet/security/advisories/GHSA-9p9m-jm8w-94p2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2WJFSBPLCNSZNHYQC4QDRDFRTEZRMD2L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5JZP4LZOSP7CUAM3GIRW6PIAWKH5VGB/https://github.com/eventlet/eventlet/security/advisories/GHSA-9p9m-jm8w-94p2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2WJFSBPLCNSZNHYQC4QDRDFRTEZRMD2L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5JZP4LZOSP7CUAM3GIRW6PIAWKH5VGB/
2021-05-07
Published