github.com/ulikunitz/xz is a package for reading and writing of xz compressed streams. Affected versions of this package are vulnerable to Denial of Service (DoS). It is possible create an infinite read loop due to the usage of the ReadUvarint and ReadVarint function when encoding/binary via invalid inputs. Note that this is a similar issue to CVE-2020-16845, affecting the Go standard library but requires its own fix. References: https://github.com/ulikunitz/xz/security/advisories/GHSA-25xm-hr59-7c27 https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMULIKUNITZXZ-607912 https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMULIKUNITZXZ-598892
Statement: In OpenShift Container Platform (OCP) and OpenShift ServiceMesh (OSSM) the affected components are behind OpenShift OAuth authentication, therefore the impact is low. In OCP before 4.7 the buildah, skopeo and podman packages include vulnerable version of github.com/ulikunitz/xz, but these OCP releases are already in the Maintenance Phase of the support, hence affected components are marked as wontfix. This may be fixed in the future.
Upstream commit: https://github.com/ulikunitz/xz/commit/69c6093c7b2397b923acf82cb378f55ab2652b9b
This issue has been addressed in the following products: RHEL-8-CNV-4.8 Via RHSA-2021:2920 https://access.redhat.com/errata/RHSA-2021:2920
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-29482
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 Via RHSA-2021:3016 https://access.redhat.com/errata/RHSA-2021:3016
This issue has been addressed in the following products: OADP-1.0-RHEL-8 Via RHSA-2022:0687 https://access.redhat.com/errata/RHSA-2022:0687
This issue has been addressed in the following products: OpenShift Service Mesh 2.0 Via RHSA-2022:1276 https://access.redhat.com/errata/RHSA-2022:1276
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2022:2183 https://access.redhat.com/errata/RHSA-2022:2183