CVE-2021-30139
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-30139 affects Alpine Linux apk-tools versions before 2.12.5, where a vulnerability in the tarball parser could lead to a buffer overflow and crash. The issue was discovered and disclosed in April 2021, impacting the package management system of Alpine Linux. The vulnerability stems from insufficient sanity checks on tar entries, where the code assumes certain fields are null-terminated without proper verification (Alpine Issue).

Technical details

The vulnerability exists in the tar parsing functionality of apk-tools where the code assumes that fields like uname, gname, linkname, magic, and name are null-terminated and uses string functions on them without prior verification. This assumption leads to an out-of-bounds read when processing tar entries. The issue occurs before signature validation, making it particularly concerning. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

When exploited, this vulnerability can cause a buffer overflow and system crash, potentially affecting the stability and availability of systems running the vulnerable versions of apk-tools. The out-of-bounds read vulnerability could lead to denial of service conditions (Alpine Issue).

Mitigation and workarounds

The vulnerability has been fixed in apk-tools versions 2.12.5 and 2.10.6. Users should upgrade to these or later versions to mitigate the risk. The fix includes adding proper null-termination checks for affected fields before using string functions on them (Alpine Issue).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management