Amazon Linux 2 Security Advisory: ALAS2-2021-1717
Advisory Released Date: 2021-11-04
Advisory Updated Date: 2021-11-04
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability. (CVE-2021-3622)
Affected Packages:
hivex
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update hivex to update your system.
aarch64:
hivex-1.3.10-6.12.amzn2.aarch64
hivex-devel-1.3.10-6.12.amzn2.aarch64
ocaml-hivex-1.3.10-6.12.amzn2.aarch64
ocaml-hivex-devel-1.3.10-6.12.amzn2.aarch64
perl-hivex-1.3.10-6.12.amzn2.aarch64
python-hivex-1.3.10-6.12.amzn2.aarch64
ruby-hivex-1.3.10-6.12.amzn2.aarch64
hivex-debuginfo-1.3.10-6.12.amzn2.aarch64
i686:
hivex-1.3.10-6.12.amzn2.i686
hivex-devel-1.3.10-6.12.amzn2.i686
ocaml-hivex-1.3.10-6.12.amzn2.i686
ocaml-hivex-devel-1.3.10-6.12.amzn2.i686
perl-hivex-1.3.10-6.12.amzn2.i686
python-hivex-1.3.10-6.12.amzn2.i686
ruby-hivex-1.3.10-6.12.amzn2.i686
hivex-debuginfo-1.3.10-6.12.amzn2.i686
src:
hivex-1.3.10-6.12.amzn2.src
x86_64:
hivex-1.3.10-6.12.amzn2.x86_64
hivex-devel-1.3.10-6.12.amzn2.x86_64
ocaml-hivex-1.3.10-6.12.amzn2.x86_64
ocaml-hivex-devel-1.3.10-6.12.amzn2.x86_64
perl-hivex-1.3.10-6.12.amzn2.x86_64
python-hivex-1.3.10-6.12.amzn2.x86_64
ruby-hivex-1.3.10-6.12.amzn2.x86_64
hivex-debuginfo-1.3.10-6.12.amzn2.x86_64