VDB

RHSA-2021%3A0436

RHSA-2021%3A0436 PUBLISHED CVSS 7.5 HIGH

A flaw was found in the math/big package of Go's standard library that causes a denial of service. Applications written in Go that use math/big via cryptographic packages, including crypto/rsa and crypto/x509, are vulnerable and can potentially cause panic via a crafted certificate chain. The highest threat from this vulnerability is to system availability.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/compliance-openscap-rhel8@sha256:54914618a94e2b88489b4c01f27920fdf0f07630e225cf10b9b4714c741baf28_amd64 as a component of Red Hat OpenShift Container Platform 4.6openshift4/compliance-openscap-rhel8@sha256:54914618a94e2b88489b4c01f27920fdf0f07630e225cf10b9b4714c741baf28_amd64
Red Hatopenshift4/compliance-rhel8-operator@sha256:a70ec5158217951c142c5f3198fb1e897050eaed39bd4c76a0a1cfde8e5375c7_amd64 as a component of Red Hat OpenShift Container Platform 4.6openshift4/compliance-rhel8-operator@sha256:a70ec5158217951c142c5f3198fb1e897050eaed39bd4c76a0a1cfde8e5375c7_amd64
Red Hatopenshift4/compliance-rhel8-operator-metadata@sha256:0f537ae9f4edc9830df58d841729c5628fc00829a64bade53adca8a4405d3d48_amd64 as a component of Red Hat OpenShift Container Platform 4.6openshift4/compliance-rhel8-operator-metadata@sha256:0f537ae9f4edc9830df58d841729c5628fc00829a64bade53adca8a4405d3d48_amd64
Red Hatopenshift4/compliance-content-rhel8@sha256:d419afa6e7579d32177fd24dc0cbfb3f8b1afe00d0f69d0678151fcf4650cf43_amd64 as a component of Red Hat OpenShift Container Platform 4.6*

Timeline

  • Feb 16, 2021 CVE Published
  • Apr 30, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›