VDB
RHSA-2021%3A0957
RHSA-2021%3A0957
PUBLISHED
CVSS 6.5 MEDIUM
A flaw detected in golang: crypto/elliptic, in which P-224 keys as generated can return incorrect inputs, reducing the strength of the cryptography. The highest threat from this vulnerability is confidentiality and integrity.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-csi-livenessprobe-rhel8@sha256:507c170097b8de0408a8afeeb9e8c945d1416810fe6b365902342895dc9d1898_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-csi-livenessprobe-rhel8@sha256:507c170097b8de0408a8afeeb9e8c945d1416810fe6b365902342895dc9d1898_amd64 |
| Red Hat | openshift4/ose-baremetal-installer-rhel8@sha256:20d8dfd4a759aed4d1e2367daa3becfba5c8bfc943c2de0496abd497210f9d00_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-baremetal-installer-rhel8@sha256:20d8dfd4a759aed4d1e2367daa3becfba5c8bfc943c2de0496abd497210f9d00_s390x |
| Red Hat | openshift4/ose-coredns@sha256:642a15691c031e36486e3908f7dee1d9d87f7d124ea42347ac7a4be9666bda03_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-coredns@sha256:642a15691c031e36486e3908f7dee1d9d87f7d124ea42347ac7a4be9666bda03_s390x |
| Red Hat | openshift4/ose-cluster-machine-approver@sha256:06c282613ca61c6c9205e106a82ad2455f9f0390edb07cafe0bb479a72c05de7_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:4f097b8b811e57a2faef4d7da9dbe8ac32b49b808b0acbfe487990c336702903_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:4f097b8b811e57a2faef4d7da9dbe8ac32b49b808b0acbfe487990c336702903_amd64 |
| Red Hat | openshift4/ose-jenkins-agent-nodejs-12-rhel8@sha256:37a05ef8982b041b4c26e7e6d18aee492e6362c5c8317df1bdff6b264920c5ae_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-jenkins-agent-nodejs-12-rhel8@sha256:37a05ef8982b041b4c26e7e6d18aee492e6362c5c8317df1bdff6b264920c5ae_amd64 |
| Red Hat | openshift4/ose-openstack-cinder-csi-driver-rhel8-operator@sha256:3b9bd8565f2d3f80b39b74b761c0e35ceba99b11bc2f2cf29a82a8ef1b45ab1b_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-openstack-cinder-csi-driver-rhel8-operator@sha256:3b9bd8565f2d3f80b39b74b761c0e35ceba99b11bc2f2cf29a82a8ef1b45ab1b_ppc64le |
| Red Hat | openshift4/ose-docker-registry@sha256:811909139d97e52ded32524c0d8c8077b73e754dae9c64873018b966b7485e58_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-docker-registry@sha256:811909139d97e52ded32524c0d8c8077b73e754dae9c64873018b966b7485e58_s390x |
| Red Hat | openshift4/ose-configmap-reloader@sha256:9e65dfaeac6f647b80c815d363ad187f1f6ca47ca9b43cb03db2c53ab9611553_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-configmap-reloader@sha256:9e65dfaeac6f647b80c815d363ad187f1f6ca47ca9b43cb03db2c53ab9611553_ppc64le |
| Red Hat | openshift4/ose-kube-storage-version-migrator-rhel8@sha256:accc52ccc0c1936ef1a58828b73fac96aaaf8b6befd84464b94ab3376f20f658_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-multus-whereabouts-ipam-cni-rhel8@sha256:ac8035acdf5b714438e2f13b74a3c6c8459979b1805d12afa1e04fcfd7c009b3_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-container-networking-plugins-rhel8@sha256:eb24f7a1d732d3792ec2dd7b9ba90d4b457daa2b663e2bd4ea9601e98e422f3f_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cluster-authentication-operator@sha256:143fd5f451243fa548c495979f85a6b2b5ce167570e428606a9949931409d1ed_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-authentication-operator@sha256:143fd5f451243fa548c495979f85a6b2b5ce167570e428606a9949931409d1ed_amd64 |
| Red Hat | openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:8dad2bdaf18adc96e4480d5089a32f7d03b984861ab5a8b7e8a6dc74a82371f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cluster-node-tuning-operator@sha256:e9cbb27605d87363ff05ebcafc6575fd9f2633ab98ce6d2e8368637926ed460f_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-node-tuning-operator@sha256:e9cbb27605d87363ff05ebcafc6575fd9f2633ab98ce6d2e8368637926ed460f_amd64 |
| Red Hat | openshift4/ose-ironic-hardware-inventory-recorder-rhel8@sha256:a538b98d173ba0b40d0c7b01f8dceb0255eada84840c85e7282612791192d083_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-ironic-hardware-inventory-recorder-rhel8@sha256:a538b98d173ba0b40d0c7b01f8dceb0255eada84840c85e7282612791192d083_amd64 |
| Red Hat | openshift4/ose-machine-api-operator@sha256:013c388445d5f4705858bd563cfd9d24798ec22b5495c8b6d3573dc9d28ec4e7_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-machine-api-operator@sha256:013c388445d5f4705858bd563cfd9d24798ec22b5495c8b6d3573dc9d28ec4e7_s390x |
| Red Hat | openshift4/ose-cluster-policy-controller-rhel8@sha256:1b4f2f8e90bc44a1f0357fab1a9670410fec6202c2c40cbe6bee60d9db2ad757_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-policy-controller-rhel8@sha256:1b4f2f8e90bc44a1f0357fab1a9670410fec6202c2c40cbe6bee60d9db2ad757_amd64 |
| Red Hat | openshift4/ovirt-csi-driver-rhel7@sha256:cab63adac91933e03ac9a8e627893fb307a6febdb2fcf8778c2240662175f08f_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ovirt-csi-driver-rhel7@sha256:cab63adac91933e03ac9a8e627893fb307a6febdb2fcf8778c2240662175f08f_amd64 |
| Red Hat | openshift4/ose-cluster-policy-controller-rhel8@sha256:d423c2b536f42c64d4abde8b5d0c6576743b8038e83529e979b0794bb51627d4_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
…and 369 more
Timeline
- Mar 30, 2021 CVE Published
- Mar 19, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:0957 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1910352 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1918750 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1922417 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1927554 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1929257 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1929371 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1929721 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1930106 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1930152 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1931401 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1931863 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1931950 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1933839 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1934645 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1935636 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1936707 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1936803 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1936861 issue
…and 16 more