VDB
RHBA-2021%3A0959
RHBA-2021%3A0959
PUBLISHED
CVSS 6.5 MEDIUM
A flaw detected in golang: crypto/elliptic, in which P-224 keys as generated can return incorrect inputs, reducing the strength of the cryptography. The highest threat from this vulnerability is confidentiality and integrity.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-sriov-operator-must-gather@sha256:9854b49bc0ef4d07ac03c3d44ed1f962089d4b8f0d029950264950389f54b545_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-operator-must-gather@sha256:9854b49bc0ef4d07ac03c3d44ed1f962089d4b8f0d029950264950389f54b545_s390x |
| Red Hat | openshift4/ose-sriov-dp-admission-controller@sha256:70f04c10f1946895796266bdfc7b859305f7a42ddaf37744918b95c135dab075_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:2ed5e9ea58f74d77174d0a5767ef9209a43c0012d3d8c6515f431b03830e2ac5_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:2ed5e9ea58f74d77174d0a5767ef9209a43c0012d3d8c6515f431b03830e2ac5_ppc64le |
| Red Hat | openshift4/ose-sriov-network-webhook@sha256:2f7b40537d9f9da07d0efcfdc0793d9d4e1154e37e583a5d9d56cf3fbbebb5a6_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-webhook@sha256:2f7b40537d9f9da07d0efcfdc0793d9d4e1154e37e583a5d9d56cf3fbbebb5a6_ppc64le |
| Red Hat | openshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:ce61fccf2f2f938baeb2b63313cec71078d3ee8a6dd7c41e6d0c154677f8cbb6_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:ce61fccf2f2f938baeb2b63313cec71078d3ee8a6dd7c41e6d0c154677f8cbb6_ppc64le |
| Red Hat | openshift4/ose-cluster-nfd-operator@sha256:f190a699562aad056fe99fef3a79c4eb198c5b5f5c552617f0fd80a17c1fab5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:bc03a7d0b232773c79e24024b0c94563621c3901a465c0cb9702e3d53856505f_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-ptp-operator@sha256:f342bdefbdcd2a2f76b4908857fb43eb18bfcd58505536b8adb2ffc3e486d35d_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-ptp-operator@sha256:f342bdefbdcd2a2f76b4908857fb43eb18bfcd58505536b8adb2ffc3e486d35d_amd64 |
| Red Hat | openshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:0b6f19b2183d86ce90d7ff038e7fe3094c79ef8f0ea261fda34c5e325f8568db_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:0b6f19b2183d86ce90d7ff038e7fe3094c79ef8f0ea261fda34c5e325f8568db_amd64 |
| Red Hat | openshift4/ose-cluster-kube-descheduler-operator@sha256:25ff8b2f966d7ad94b9f8517db2043a4256c09fcbe375b86c9b07ea07d657f67_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-sriov-cni@sha256:c76d9c7956e1f34dc4fa8342ac61ccf900cf4f2da5173e4ea42af8eb283b7719_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cluster-capacity@sha256:492117fd5a8551332c7f21a285e03d44b0981f6b1c2756b07893a19e1934f686_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-capacity@sha256:492117fd5a8551332c7f21a285e03d44b0981f6b1c2756b07893a19e1934f686_ppc64le |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:a0448082f9deeda2de78a0e6ce075a0ba71838c84470933dc29abc3be6944443_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-operator@sha256:a0448082f9deeda2de78a0e6ce075a0ba71838c84470933dc29abc3be6944443_s390x |
| Red Hat | openshift4/ose-local-storage-operator@sha256:d22b0fe75a8772d3f804d09f9de210df36e5e858947d6f6fe246748410a5751b_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-sriov-cni@sha256:05b0cad70b5bc71574cb80f725c32da2c7251c2095a417a40fb008771216fe80_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-cni@sha256:05b0cad70b5bc71574cb80f725c32da2c7251c2095a417a40fb008771216fe80_amd64 |
| Red Hat | openshift4/ose-leader-elector-rhel8@sha256:54793801d1d9f0922b76ad454bfed65434f946e13a2ca0b57c67805126832c60_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-leader-elector-rhel8@sha256:54793801d1d9f0922b76ad454bfed65434f946e13a2ca0b57c67805126832c60_amd64 |
| Red Hat | openshift4/ose-leader-elector-rhel8@sha256:914e5ea07786e32c0e1b2ff9d88f85e4943547cec0b7ef32b5479d116a35cdd3_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-leader-elector-rhel8@sha256:914e5ea07786e32c0e1b2ff9d88f85e4943547cec0b7ef32b5479d116a35cdd3_ppc64le |
| Red Hat | openshift4/ose-sriov-infiniband-cni@sha256:0110a78cc1b4ea1acb0f83e83baa99bfd4b20f417317bda3e8570ffb1ab2fe65_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-ptp-operator@sha256:0e2caaaa1a4736af15b7fec18be89517971f96f9f3513b3c55727975c5824318_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-descheduler@sha256:3ae1a690da2232f3ed1aec565f332738a299f1b1e49a56583b3c54c95748d131_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-descheduler@sha256:3ae1a690da2232f3ed1aec565f332738a299f1b1e49a56583b3c54c95748d131_amd64 |
…and 103 more
Timeline
- Mar 30, 2021 CVE Published
- Mar 19, 2026 CVE Updated
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHBA-2021:0959 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1941567 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhba-2021_0959.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3114 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1918750 issue
- https://www.cve.org/CVERecord?id=CVE-2021-3114 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3114 advisory
- https://groups.google.com/g/golang-announce/c/mperVMGa98w advisory