VDB

RHBA-2021%3A1365

RHBA-2021%3A1365 PUBLISHED CVSS 8.600000381469727 HIGH

A flaw was found in github.com/gogo/protobuf before 1.3.2 that allows an out-of-bounds access when unmarshalling certain protobuf objects. This flaw allows a remote attacker to send crafted protobuf messages, causing panic and resulting in a denial of service. The highest threat from this vulnerability is to availability.

Risk Scores

CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-openshift-state-metrics-rhel8@sha256:98daff6929c08f3167c65be7430c650afbf772a5fba8a314a4a91177bdaba0ad_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-openshift-state-metrics-rhel8@sha256:98daff6929c08f3167c65be7430c650afbf772a5fba8a314a4a91177bdaba0ad_amd64
Red Hatopenshift4/ose-cluster-openshift-controller-manager-operator@sha256:dcc83e3b81233c8b4953df1c134ab4af7aa92c84b27714913a4f37766647c30f_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-cluster-openshift-controller-manager-operator@sha256:dcc83e3b81233c8b4953df1c134ab4af7aa92c84b27714913a4f37766647c30f_amd64
Red Hatopenshift4/ose-baremetal-rhel8-operator@sha256:1c4997fc33515d817d79e493f9a818a7a17791bcb03495c1e05b233bf29ea1c2_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-baremetal-rhel8-operator@sha256:1c4997fc33515d817d79e493f9a818a7a17791bcb03495c1e05b233bf29ea1c2_s390x
Red Hatopenshift4/ose-baremetal-installer-rhel8@sha256:dc6c744ce3384355981bcfd56fe7a5d403c7e2809a6f451f3745abf5e5247860_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-baremetal-installer-rhel8@sha256:dc6c744ce3384355981bcfd56fe7a5d403c7e2809a6f451f3745abf5e5247860_s390x
Red Hatopenshift4/ose-cluster-openshift-apiserver-operator@sha256:3bdd2b4158396cb711678d472cedf716f2add74b1fd0bcc5f8cb66bde9705135_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-cluster-openshift-apiserver-operator@sha256:3bdd2b4158396cb711678d472cedf716f2add74b1fd0bcc5f8cb66bde9705135_ppc64le
Red Hatopenshift4/ose-haproxy-router@sha256:f5857c319d70b51db9b89927c8fbdb3b5dee23424cb532f03e9af1d3f70a896b_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-haproxy-router@sha256:f5857c319d70b51db9b89927c8fbdb3b5dee23424cb532f03e9af1d3f70a896b_ppc64le
Red Hatopenshift4/ose-cluster-dns-operator@sha256:4f5c201deacb6321bd71726ca60b607281db4c0c65b62403b3299903c26cc721_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-cluster-dns-operator@sha256:4f5c201deacb6321bd71726ca60b607281db4c0c65b62403b3299903c26cc721_ppc64le
Red Hatopenshift4/ose-ovirt-machine-controllers-rhel8@sha256:cc7df70a764d385482580d8dd273c113b6efa51acf60ae09b4ed848c7f412563_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-ovirt-machine-controllers-rhel8@sha256:cc7df70a764d385482580d8dd273c113b6efa51acf60ae09b4ed848c7f412563_amd64
Red Hatopenshift4/ose-grafana@sha256:7d175c95b5d0a99ea6f675fbdc55d439120d3cabb04104e5a78ff674babbb5b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-grafana@sha256:7d175c95b5d0a99ea6f675fbdc55d439120d3cabb04104e5a78ff674babbb5b7_ppc64le
Red Hatopenshift4/ose-grafana@sha256:6a2b2218bb65bc3fdef3c9fee301d263d04749d985325b8f39fc23c2838f38f2_s390x as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ovirt-csi-driver-rhel8-operator@sha256:c2f4358f16af1bfc3a247a6906c4c8be6f123676aa08e1198215ca8de59bfc7f_ppc64le as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-operator-lifecycle-manager@sha256:622ec169674a756912fb15fc4476e7c53b5e0489c1572278d431628f8f6de0a5_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-operator-lifecycle-manager@sha256:622ec169674a756912fb15fc4476e7c53b5e0489c1572278d431628f8f6de0a5_s390x
Red Hatopenshift4/ose-prometheus-operator@sha256:1f2f249703f6c906d7a876c471d100a2f7833e5176d55e17ddc04f35b0692257_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-prometheus-operator@sha256:1f2f249703f6c906d7a876c471d100a2f7833e5176d55e17ddc04f35b0692257_amd64
Red Hatopenshift4/ose-console-operator@sha256:16e7ec3310e295e10b8b2d05b94a9859cacea4ccebfb3306e7379d990cf81571_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-console-operator@sha256:16e7ec3310e295e10b8b2d05b94a9859cacea4ccebfb3306e7379d990cf81571_s390x
Red Hatopenshift4/ose-docker-registry@sha256:4c08ea56c982e70b216365f91676cd5d2448550aa3a0a6c3d84f72ef9f35e281_ppc64le as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-operator-registry@sha256:05239b6f307755f15a97b726c3203166b9c03ac2663f319f5323b75180d406f6_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-operator-registry@sha256:05239b6f307755f15a97b726c3203166b9c03ac2663f319f5323b75180d406f6_amd64
Red Hatopenshift4/ose-machine-config-operator@sha256:e24d373681c97f2b556afc9b58ff6adb7e71c1c11aa866bad62c313fdc6933a6_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-machine-config-operator@sha256:e24d373681c97f2b556afc9b58ff6adb7e71c1c11aa866bad62c313fdc6933a6_ppc64le
Red Hatopenshift4/ose-sdn-rhel8@sha256:2d309ffdc9da2970239f9e9d736256382051614d40d4ae210415ae0a86b25673_ppc64le as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-kube-storage-version-migrator-rhel8@sha256:4bc25e5ca4d327ca52322a2146d98b31214156de21a2b17408b2e999b1ce4769_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-kube-storage-version-migrator-rhel8@sha256:4bc25e5ca4d327ca52322a2146d98b31214156de21a2b17408b2e999b1ce4769_amd64
Red Hatopenshift4/ose-csi-snapshot-controller-rhel8@sha256:9efebc7a6e98b758e1af053c25a493429fc3853a433bc85258c67b9559ed81b1_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-csi-snapshot-controller-rhel8@sha256:9efebc7a6e98b758e1af053c25a493429fc3853a433bc85258c67b9559ed81b1_amd64

…and 370 more

Timeline

  • May 4, 2021 CVE Published
  • Mar 26, 2026 CVE Updated
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›