Amazon Linux 2 Security Advisory: ALAS-2021-1717
Advisory Release Date: 2021-10-28 23:19 Pacific
Advisory Updated Date: 2021-11-04 18:03 Pacific
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability. (CVE-2021-3622)
Affected Packages:
hivex
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update hivex to update your system.
aarch64:
hivex-1.3.10-6.12.amzn2.aarch64
hivex-devel-1.3.10-6.12.amzn2.aarch64
ocaml-hivex-1.3.10-6.12.amzn2.aarch64
ocaml-hivex-devel-1.3.10-6.12.amzn2.aarch64
perl-hivex-1.3.10-6.12.amzn2.aarch64
python-hivex-1.3.10-6.12.amzn2.aarch64
ruby-hivex-1.3.10-6.12.amzn2.aarch64
hivex-debuginfo-1.3.10-6.12.amzn2.aarch64
i686:
hivex-1.3.10-6.12.amzn2.i686
hivex-devel-1.3.10-6.12.amzn2.i686
ocaml-hivex-1.3.10-6.12.amzn2.i686
ocaml-hivex-devel-1.3.10-6.12.amzn2.i686
perl-hivex-1.3.10-6.12.amzn2.i686
python-hivex-1.3.10-6.12.amzn2.i686
ruby-hivex-1.3.10-6.12.amzn2.i686
hivex-debuginfo-1.3.10-6.12.amzn2.i686
src:
hivex-1.3.10-6.12.amzn2.src
x86_64:
hivex-1.3.10-6.12.amzn2.x86_64
hivex-devel-1.3.10-6.12.amzn2.x86_64
ocaml-hivex-1.3.10-6.12.amzn2.x86_64
ocaml-hivex-devel-1.3.10-6.12.amzn2.x86_64
perl-hivex-1.3.10-6.12.amzn2.x86_64
python-hivex-1.3.10-6.12.amzn2.x86_64
ruby-hivex-1.3.10-6.12.amzn2.x86_64
hivex-debuginfo-1.3.10-6.12.amzn2.x86_64