Lucene search

K
ibmIBM6E62C5725D1943EB9B8A092A47438C020F5C84443BF595654502907DBF8ACBAA
HistoryDec 21, 2021 - 5:51 p.m.

Security Bulletin: IBM Event Streams affected by potential buffer overflow in Golang (CVE-2021-38297)

2021-12-2117:51:25
www.ibm.com
16
ibm event streams
golang
buffer overflow
cve-2021-38297
ibm fix central
upgrading and migrating

EPSS

0.005

Percentile

76.8%

Summary

IBM Event Streams affected by vulnerabilitiy in Golang which may result in a buffer overflow (CVE-2021-38297)

Vulnerability Details

CVEID:CVE-2021-38297
**DESCRIPTION:**Golang Go is vulnerable to a buffer overflow, caused by improper bounds checking when invoking functions from WASM modules. By passing very large arguments, a remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/211507 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Event Streams 2019.4.1, 2019.4.2, 2019.4.3, 2019.4.4
IBM Event Streams 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.4.0

Remediation/Fixes

IBM Event Streams (Helm-based releases)

IBM Event Streams (Continuous Delivery)

IBM Event Streams (Extended Update Support)

Workarounds and Mitigations

None