Vulnerability Description
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rpm | Rpm | >= 4.15.0, < 4.15.1.3 |
| Redhat | Enterprise Linux | 8.0 |
| Fedoraproject | Fedora | 32 |
| Starwindsoftware | Starwind Virtual San | v8 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1934125Issue TrackingPatchThird Party Advisory
- https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202107-43Third Party Advisory
- https://www.starwindsoftware.com/security/sw-20220805-0002/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1934125Issue TrackingPatchThird Party Advisory
- https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202107-43Third Party Advisory
- https://www.starwindsoftware.com/security/sw-20220805-0002/Third Party Advisory
FAQ
What is CVE-2021-20271?
CVE-2021-20271 is a vulnerability with a CVSS score of 7.0 (HIGH). A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature h...
How severe is CVE-2021-20271?
CVE-2021-20271 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20271?
Check the references section above for vendor advisories and patch information. Affected products include: Rpm Rpm, Redhat Enterprise Linux, Fedoraproject Fedora, Starwindsoftware Starwind Virtual San.