CVE-2021-21419
Vulnerability Summary
Timeline
Description
Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame. A patch in version 0.31.0 restricts websocket frame to reasonable limits. As a workaround, restricting memory usage via OS limits would help against overall machine exhaustion, but there is no workaround to protect Eventlet process.
CVSS Metrics
- v4.0•MEDIUM•Score: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 1.81%• Percentile: 78%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- debian•python-eventlet
< 0.26.1-7 | < 0.26.1-7 | < 0.26.1-7 | < 0.26.1-7
- eventlet•eventlet
≥ 0.10, < 0.31.0
- fedoraproject•fedora
33 | 34
- PyPI•eventlet
≥ 0.10.0, < 0.31.0 | ≥ 0.10, < 0.31.0
- redhat•python-eventlet
< 0:0.25.2-5.el8ost.1
- redhat•python3-eventlet
< 0:0.25.2-5.el8ost.1
References (16)
- https://github.com/eventlet/eventlet/security/advisories/GHSA-9p9m-jm8w-94p2
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5JZP4LZOSP7CUAM3GIRW6PIAWKH5VGB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2WJFSBPLCNSZNHYQC4QDRDFRTEZRMD2L/
- https://nvd.nist.gov/vuln/detail/CVE-2021-21419
- https://github.com/eventlet/eventlet/commit/1412f5e4125b4313f815778a1acb4d3336efcd07
- https://github.com/eventlet/eventlet
- https://github.com/pypa/advisory-database/tree/main/vulns/eventlet/PYSEC-2021-12.yaml
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WJFSBPLCNSZNHYQC4QDRDFRTEZRMD2L
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R5JZP4LZOSP7CUAM3GIRW6PIAWKH5VGB
- https://security-tracker.debian.org/tracker/CVE-2021-21419
- https://access.redhat.com/errata/RHSA-2021:5071
- https://access.redhat.com/security/updates/classification/#moderate
- https://bugzilla.redhat.com/show_bug.cgi?id=1958407
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_5071.json
- https://access.redhat.com/security/cve/CVE-2021-21419
- https://www.cve.org/CVERecord?id=CVE-2021-21419