Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-23218: security/0002.md at main · Mirantis/security

When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.

CVE
#vulnerability#dos

Permalink

Memory Leak in Mirantis Container Runtime (MCR) running in FIPS mode causes a Denial of Service (DoS)****Release Date

2022/01/10

Overview

When running with FIPS mode enabled, Mirantis Container Runtime leaks memory during TLS Handshakes which could be abused to cause a denial of service.

Affected Products

Mirantis Container Runtime (MCR) version 20.10.8

Vulnerability Information****CVE Identifier

CVE-2021-23218

CVSSv3.1

5.3 (Medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CWEs

CWE-401

Mitigations

FIPS mode is not the default mode of operation

Work arounds

Disable FIPS mode

Acknowledgements

Found by Mirantis PSIRT

Disclosure Timeline

2022/01/10: public advisory released

2021/12/21: 20.10.8 released

2021/12/09: Mirantis PSIRT reported vulnerability to MCR team

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907