VDB
RHEA-2021:3941
RHEA-2021:3941
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in golang. A panic can be triggered by an attacker in a privileged network position without access to the server certificate's private key, as long as a trusted ECDSA or Ed25519 certificate for the server exists (or can be issued), or the client is configured with Config.InsecureSkipVerify. Clients that disable all TLS_RSA cipher suites (that is, TLS 1.0–1.2 cipher suites without ECDHE), as well as TLS 1.3-only clients, are unaffected.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-sandboxed-containers-tech-preview/osc-operator-bundle@sha256:a91cee14f47824ce49759628d06bf4e48276e67dae00b50123d3233d78531720_amd64 as a component of OpenShift Sandboxed Containers 1.1.0 | openshift-sandboxed-containers-tech-preview/osc-operator-bundle@sha256:a91cee14f47824ce49759628d06bf4e48276e67dae00b50123d3233d78531720_amd64 |
| Red Hat | openshift-sandboxed-containers-tech-preview/osc-must-gather-rhel8@sha256:379aa6f59d25af015dba6a450851e7efb5b6ec6ac03e07f6325a00ab4cc43e3d_amd64 as a component of OpenShift Sandboxed Containers 1.1.0 | * |
| Red Hat | openshift-sandboxed-containers-tech-preview/osc-rhel8-operator@sha256:743499367a4891d0f6d4aae9bb1b370893c3b2ea492c59464192da305145f1b7_amd64 as a component of OpenShift Sandboxed Containers 1.1.0 | openshift-sandboxed-containers-tech-preview/osc-rhel8-operator@sha256:743499367a4891d0f6d4aae9bb1b370893c3b2ea492c59464192da305145f1b7_amd64 |
Timeline
- Oct 20, 2021 CVE Published
- Mar 27, 2026 CVE Updated
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHEA-2021:3941 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhea-2021_3941.json advisory
- https://access.redhat.com/security/cve/CVE-2021-34558 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1983596 issue
- https://www.cve.org/CVERecord?id=CVE-2021-34558 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-34558 advisory
- https://golang.org/doc/devel/release#go1.15.minor advisory
- https://golang.org/doc/devel/release#go1.16.minor advisory