-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libtirpc security update Advisory ID: RHSA-2022:8400-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8400 Issue date: 2022-11-15 CVE Names: CVE-2021-46828 ==================================================================== 1. Summary: An update for libtirpc is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The libtirpc packages contain SunLib's implementation of transport-independent remote procedure call (TI-RPC) documentation, which includes a library required by programs in the nfs-utils and rpcbind packages. Security Fix(es): * libtirpc: DoS vulnerability with lots of connections (CVE-2021-46828) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2109352 - CVE-2021-46828 libtirpc: DoS vulnerability with lots of connections 2118157 - CVE-2021-46828 libtirpc: Upgrade to the latest upstream release libtirpc-1.3.3 [rhel-9.1.0] 6. Package List: Red Hat Enterprise Linux BaseOS (v. 9): Source: libtirpc-1.3.3-0.el9.src.rpm aarch64: libtirpc-1.3.3-0.el9.aarch64.rpm libtirpc-debuginfo-1.3.3-0.el9.aarch64.rpm libtirpc-debugsource-1.3.3-0.el9.aarch64.rpm ppc64le: libtirpc-1.3.3-0.el9.ppc64le.rpm libtirpc-debuginfo-1.3.3-0.el9.ppc64le.rpm libtirpc-debugsource-1.3.3-0.el9.ppc64le.rpm s390x: libtirpc-1.3.3-0.el9.s390x.rpm libtirpc-debuginfo-1.3.3-0.el9.s390x.rpm libtirpc-debugsource-1.3.3-0.el9.s390x.rpm x86_64: libtirpc-1.3.3-0.el9.i686.rpm libtirpc-1.3.3-0.el9.x86_64.rpm libtirpc-debuginfo-1.3.3-0.el9.i686.rpm libtirpc-debuginfo-1.3.3-0.el9.x86_64.rpm libtirpc-debugsource-1.3.3-0.el9.i686.rpm libtirpc-debugsource-1.3.3-0.el9.x86_64.rpm Red Hat CodeReady Linux Builder (v. 9): aarch64: libtirpc-debuginfo-1.3.3-0.el9.aarch64.rpm libtirpc-debugsource-1.3.3-0.el9.aarch64.rpm libtirpc-devel-1.3.3-0.el9.aarch64.rpm ppc64le: libtirpc-debuginfo-1.3.3-0.el9.ppc64le.rpm libtirpc-debugsource-1.3.3-0.el9.ppc64le.rpm libtirpc-devel-1.3.3-0.el9.ppc64le.rpm s390x: libtirpc-debuginfo-1.3.3-0.el9.s390x.rpm libtirpc-debugsource-1.3.3-0.el9.s390x.rpm libtirpc-devel-1.3.3-0.el9.s390x.rpm x86_64: libtirpc-debuginfo-1.3.3-0.el9.i686.rpm libtirpc-debuginfo-1.3.3-0.el9.x86_64.rpm libtirpc-debugsource-1.3.3-0.el9.i686.rpm libtirpc-debugsource-1.3.3-0.el9.x86_64.rpm libtirpc-devel-1.3.3-0.el9.i686.rpm libtirpc-devel-1.3.3-0.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-46828 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is. More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY3OMRtzjgjWX9erEAQhd+Q//Y1X+e2OsGEBUqBRBDs2msHFginbvg7uZ cbGMYGbb7u16+S0BgZEIUkmtCPSR2Tm2BjLjceTiQSR7rMhpM61O1ab3zPd42NvP BcHnnu5alTi+LfSBippNJjR4TKm1JzON3ny9im6lz/icP14mrVQLpn0JdJNwUCVL FLe8v8ZwSkTSFK6YUIb8QcKVJJH5NgWxQBQ4BK7xgCmx7DCRV97G7Z5a08fZf6Hn BxIio3Jj6AzDAi7Llw+VDb7KI7p918Esq1Sl3w2kwXexmcXda6r5ftG7SjEvf8Sp d4QPEWU9wJrEqx13rYh8g/8xAF1jTzLLBgvfnxnNQupvrgskss5qrDhTps/GaSVg qk7RWyDsURRPTAtCisW+EO3PIXCL9101e+kroLC2w44hqqdTi86X03Fizn3xDuZ1 48YO2sOc6M+ipzA5YUWgMMEmT5YDOQGhflDNf9wbxcLmzFWz5Xa0ui3UWQJ8lrhH 4B4C7SYoHsuNUNUYDzqjnxB8QgpycDuVBHKB/eSqYHXBUOdPixZfrAKLI/h/LRfK LhzogIsCy4tmw4txNcgvb0qhq6ehaU9cRmqlxbtRsvthtANorTrC8Slq1kT51OXJ W5aaFyfGGC/+L8VnB3q0xWx4dzaonEh49aZdTjnqUCfM5ItkqsXE8MwwShn+Rr9W E7LBqCWDqRw=u4dV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The libtirpc packages contain SunLib's implementation of
transport-independent remote procedure call (TI-RPC) documentation, which
includes a library required by programs in the nfs-utils and rpcbind
packages.
Security Fix(es):
* libtirpc: DoS vulnerability with lots of connections (CVE-2021-46828)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 9.1 Release Notes linked from the References section.
https://access.redhat.com/security/cve/CVE-2021-46828 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.1_release_notes/index
Red Hat Enterprise Linux BaseOS (v. 9):
Source:
libtirpc-1.3.3-0.el9.src.rpm
aarch64:
libtirpc-1.3.3-0.el9.aarch64.rpm
libtirpc-debuginfo-1.3.3-0.el9.aarch64.rpm
libtirpc-debugsource-1.3.3-0.el9.aarch64.rpm
ppc64le:
libtirpc-1.3.3-0.el9.ppc64le.rpm
libtirpc-debuginfo-1.3.3-0.el9.ppc64le.rpm
libtirpc-debugsource-1.3.3-0.el9.ppc64le.rpm
s390x:
libtirpc-1.3.3-0.el9.s390x.rpm
libtirpc-debuginfo-1.3.3-0.el9.s390x.rpm
libtirpc-debugsource-1.3.3-0.el9.s390x.rpm
x86_64:
libtirpc-1.3.3-0.el9.i686.rpm
libtirpc-1.3.3-0.el9.x86_64.rpm
libtirpc-debuginfo-1.3.3-0.el9.i686.rpm
libtirpc-debuginfo-1.3.3-0.el9.x86_64.rpm
libtirpc-debugsource-1.3.3-0.el9.i686.rpm
libtirpc-debugsource-1.3.3-0.el9.x86_64.rpm
Red Hat CodeReady Linux Builder (v. 9):
aarch64:
libtirpc-debuginfo-1.3.3-0.el9.aarch64.rpm
libtirpc-debugsource-1.3.3-0.el9.aarch64.rpm
libtirpc-devel-1.3.3-0.el9.aarch64.rpm
ppc64le:
libtirpc-debuginfo-1.3.3-0.el9.ppc64le.rpm
libtirpc-debugsource-1.3.3-0.el9.ppc64le.rpm
libtirpc-devel-1.3.3-0.el9.ppc64le.rpm
s390x:
libtirpc-debuginfo-1.3.3-0.el9.s390x.rpm
libtirpc-debugsource-1.3.3-0.el9.s390x.rpm
libtirpc-devel-1.3.3-0.el9.s390x.rpm
x86_64:
libtirpc-debuginfo-1.3.3-0.el9.i686.rpm
libtirpc-debuginfo-1.3.3-0.el9.x86_64.rpm
libtirpc-debugsource-1.3.3-0.el9.i686.rpm
Read the Full Advisory
An update for libtirpc is now available for Red Hat Enterprise Linux 9.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64
2109352 - CVE-2021-46828 libtirpc: DoS vulnerability with lots of connections
2118157 - CVE-2021-46828 libtirpc: Upgrade to the latest upstream release libtirpc-1.3.3 [rhel-9.1.0]
Get the latest Linux and open source security news straight to your inbox.