VDB

RHBA-2021%3A3760

RHBA-2021%3A3760 PUBLISHED CVSS 8.600000381469727 HIGH

A flaw was found in github.com/gogo/protobuf before 1.3.2 that allows an out-of-bounds access when unmarshalling certain protobuf objects. This flaw allows a remote attacker to send crafted protobuf messages, causing panic and resulting in a denial of service. The highest threat from this vulnerability is to availability.

Risk Scores

CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-ansible-operator@sha256:fb654df45446204aa84321073d433d3796f86ddcbd4ad946510b49962005992f_amd64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-ansible-operator@sha256:fb654df45446204aa84321073d433d3796f86ddcbd4ad946510b49962005992f_amd64
Red Hatopenshift4/ose-ptp-operator@sha256:3c610a68e5cb466e1704271ec587431bfc6b5b49def2824a6af82f3e2264ca6b_ppc64le as a component of Red Hat OpenShift Container Platform 4.9*
Red Hatopenshift4/ose-node-problem-detector-rhel8@sha256:1dd95f3bd68881b01046bb097a64ddf491bd6d1484550595c99a7f8da17ff99a_s390x as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-node-problem-detector-rhel8@sha256:1dd95f3bd68881b01046bb097a64ddf491bd6d1484550595c99a7f8da17ff99a_s390x
Red Hatopenshift4/ose-sriov-network-device-plugin@sha256:fa67b4154629933599dc7bdcd76684d2b6670ad22dd721df8f3c05f3cf739d64_arm64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-sriov-network-device-plugin@sha256:fa67b4154629933599dc7bdcd76684d2b6670ad22dd721df8f3c05f3cf739d64_arm64
Red Hatopenshift4/ose-egress-dns-proxy@sha256:18e15f6a75bf2874a12d74b5c946555fd0ad3a75f6d88fbc21ab35fc5c4471cf_s390x as a component of Red Hat OpenShift Container Platform 4.9*
Red Hatopenshift4/ose-csi-node-driver-registrar-rhel8@sha256:e611dd0b5c05c38fd355018ba9bd06da121db93e0a9b0f24b6d866cef7b3c902_s390x as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-csi-node-driver-registrar-rhel8@sha256:e611dd0b5c05c38fd355018ba9bd06da121db93e0a9b0f24b6d866cef7b3c902_s390x
Red Hatopenshift4/ose-egress-dns-proxy@sha256:a563faaeb7da3bbd5f452b50a87faebaaefe14332738133caefd6c34f125ff82_arm64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-egress-dns-proxy@sha256:a563faaeb7da3bbd5f452b50a87faebaaefe14332738133caefd6c34f125ff82_arm64
Red Hatopenshift4/ose-sriov-operator-must-gather@sha256:8b472a1c805581adb42257c92cd261c1fa00d209191179c081bd1d9453b4491d_amd64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-sriov-operator-must-gather@sha256:8b472a1c805581adb42257c92cd261c1fa00d209191179c081bd1d9453b4491d_amd64
Red Hatopenshift4/ose-openshift-proxy-pull-test-rhel8@sha256:bd0dfcb0769205f6ab7316cbee99bf9785f8e997dca2554fae40a142445e8502_ppc64le as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:bd0dfcb0769205f6ab7316cbee99bf9785f8e997dca2554fae40a142445e8502_ppc64le
Red Hatopenshift4/ose-descheduler@sha256:91519f086ee786ce50e5b1bbcc1cacad6966b545be331f37e67e9d7df1d40b07_s390x as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-descheduler@sha256:91519f086ee786ce50e5b1bbcc1cacad6966b545be331f37e67e9d7df1d40b07_s390x
Red Hatopenshift4/ose-service-idler-rhel8@sha256:71ad0530140bc089141befd58008c9f5fe92dde7ed94b7665cd70ec5ebb82196_s390x as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-service-idler-rhel8@sha256:71ad0530140bc089141befd58008c9f5fe92dde7ed94b7665cd70ec5ebb82196_s390x
Red Hatopenshift4/ose-sriov-network-webhook@sha256:d22dd89a58e20bb58c5411c3823d4cdc11d0d6f593575f7c15d48cc0698216fe_amd64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-sriov-network-webhook@sha256:d22dd89a58e20bb58c5411c3823d4cdc11d0d6f593575f7c15d48cc0698216fe_amd64
Red Hatopenshift4/ose-kube-rbac-proxy@sha256:ca275db0dad83a985fefe7af0c03c38748757b7c8ecf1d43a993c816b8788c29_s390x as a component of Red Hat OpenShift Container Platform 4.9*
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:4481bb6cb16914d98d91d788c509ba5b2e1ff24a3d5fa94451bbab8ba6d9e896_arm64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-operator-sdk-rhel8@sha256:4481bb6cb16914d98d91d788c509ba5b2e1ff24a3d5fa94451bbab8ba6d9e896_arm64
Red Hatopenshift4/ose-local-storage-operator@sha256:c945d70cf98c2f573bba22b53b6aa7b64c565e4ddb9bb3e86317e2ebdb2172ec_amd64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-local-storage-operator@sha256:c945d70cf98c2f573bba22b53b6aa7b64c565e4ddb9bb3e86317e2ebdb2172ec_amd64
Red Hatopenshift4/ose-sriov-network-operator@sha256:1815ab082e7fa8e4525230bfa150db9ced69c878f69e1e8f930a9ea398dd93be_amd64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-sriov-network-operator@sha256:1815ab082e7fa8e4525230bfa150db9ced69c878f69e1e8f930a9ea398dd93be_amd64
Red Hatopenshift4/ose-csi-external-provisioner-rhel8@sha256:c78cc84c30bf39cc47b37924465118ed5d9f8d8907a1f5f0019ae1254503f8af_amd64 as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-csi-external-provisioner-rhel8@sha256:c78cc84c30bf39cc47b37924465118ed5d9f8d8907a1f5f0019ae1254503f8af_amd64
Red Hatopenshift4/ose-egress-http-proxy@sha256:f4b492189bce39cedec7e3b13ce63e33facac39d494aa300c0a7952b56cde7b3_s390x as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-egress-http-proxy@sha256:f4b492189bce39cedec7e3b13ce63e33facac39d494aa300c0a7952b56cde7b3_s390x
Red Hatopenshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:aa9e5393a8ed2726182be5a32a5bf4e57479c182df1c7aae07509d2214b06ddd_arm64 as a component of Red Hat OpenShift Container Platform 4.9*
Red Hatopenshift4/ose-csi-livenessprobe-rhel8@sha256:870445ab6879bdd11111036d0fc07f21d74cef1f36d3020567b8b4855d30492e_s390x as a component of Red Hat OpenShift Container Platform 4.9openshift4/ose-csi-livenessprobe-rhel8@sha256:870445ab6879bdd11111036d0fc07f21d74cef1f36d3020567b8b4855d30492e_s390x

…and 184 more

Timeline

  • Oct 18, 2021 CVE Published
  • Mar 26, 2026 CVE Updated
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›