VDB
RHSA-2021%3A1225
RHSA-2021%3A1225
PUBLISHED
CVSS 8.600000381469727 HIGH
A flaw was found in github.com/gogo/protobuf before 1.3.2 that allows an out-of-bounds access when unmarshalling certain protobuf objects. This flaw allows a remote attacker to send crafted protobuf messages, causing panic and resulting in a denial of service. The highest threat from this vulnerability is to availability.
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-csi-external-resizer-rhel8@sha256:d9898bd020112237b09a2b7aaf4fe93890e3a7ab61fa0aef9576d43d8c4574a0_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-haproxy-router@sha256:24051bc2bdbb829935e8b8fcc19a47ed499c9da5747e4260c9e7bf7a2b8838e5_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-haproxy-router@sha256:24051bc2bdbb829935e8b8fcc19a47ed499c9da5747e4260c9e7bf7a2b8838e5_s390x |
| Red Hat | openshift4/ose-sdn-rhel8@sha256:ea4b1b40d91c93a98bd1c9a4fe63f5897fd59c7c9a662b7b0ff29c3624698e31_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sdn-rhel8@sha256:ea4b1b40d91c93a98bd1c9a4fe63f5897fd59c7c9a662b7b0ff29c3624698e31_amd64 |
| Red Hat | openshift4/ose-docker-builder@sha256:b63d3a59e7bab7a63b291c0bc15531f1c3f2e43280e68c7e7cdfd55c68be8c25_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-docker-builder@sha256:b63d3a59e7bab7a63b291c0bc15531f1c3f2e43280e68c7e7cdfd55c68be8c25_amd64 |
| Red Hat | openshift4/ose-cluster-etcd-rhel8-operator@sha256:67e20563540c439cdd5cd1da8746c80370d20ac21186254f167a78113970f6d9_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-etcd-rhel8-operator@sha256:67e20563540c439cdd5cd1da8746c80370d20ac21186254f167a78113970f6d9_amd64 |
| Red Hat | openshift4/ose-cluster-baremetal-operator-rhel8@sha256:29db7d3cc5c74945d256da53858a36b633a481d53dda257ba37ef255ef677141_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-baremetal-operator-rhel8@sha256:29db7d3cc5c74945d256da53858a36b633a481d53dda257ba37ef255ef677141_amd64 |
| Red Hat | openshift4/ose-csi-snapshot-controller@sha256:0998f4e3d1834d2fcf3f98c9ca679d3efde9f3778b267ae8fcab6cfb01e34b03_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-csi-snapshot-controller@sha256:0998f4e3d1834d2fcf3f98c9ca679d3efde9f3778b267ae8fcab6cfb01e34b03_amd64 |
| Red Hat | openshift4/ose-grafana@sha256:d757d7fbec9a4f891659495c4c4e7c3579f190d8b5ee48a344d9e2826f71b2b6_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-grafana@sha256:d757d7fbec9a4f891659495c4c4e7c3579f190d8b5ee48a344d9e2826f71b2b6_s390x |
| Red Hat | openshift4/ose-csi-external-provisioner@sha256:c75b60e902fd3a670506fc4f32072d3bf9a9be5f7b59e7cee5231b2b5cd194d3_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-csi-external-provisioner@sha256:c75b60e902fd3a670506fc4f32072d3bf9a9be5f7b59e7cee5231b2b5cd194d3_s390x |
| Red Hat | openshift4/ose-baremetal-installer-rhel8@sha256:2cdf659ba7aab6f4079b6c962435f1ae0fe610e77b82c0622bba7728244acb66_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-baremetal-installer-rhel8@sha256:2cdf659ba7aab6f4079b6c962435f1ae0fe610e77b82c0622bba7728244acb66_amd64 |
| Red Hat | openshift4/ose-etcd@sha256:d3a5ed1432ba95e3d2ced21644eb0a06df68c8a7ffb433a42cb97b5585bb5e65_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-etcd@sha256:d3a5ed1432ba95e3d2ced21644eb0a06df68c8a7ffb433a42cb97b5585bb5e65_ppc64le |
| Red Hat | openshift4/ose-jenkins@sha256:2082e3109c56bb94e8aab6e328fa32ae455d00fef89e287a20a822e177af6e77_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-jenkins@sha256:2082e3109c56bb94e8aab6e328fa32ae455d00fef89e287a20a822e177af6e77_s390x |
| Red Hat | openshift4/ose-console@sha256:ee2092483c25126fbabb0534e8ae6ad7f00a1bef156c9b99df92644c5620b982_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-console@sha256:ee2092483c25126fbabb0534e8ae6ad7f00a1bef156c9b99df92644c5620b982_ppc64le |
| Red Hat | openshift4/ose-jenkins-agent-maven@sha256:35096b46848357076ede0ad2472b1b37c330b9a766a5fa0c7005ab3e86b750d8_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-jenkins-agent-maven@sha256:35096b46848357076ede0ad2472b1b37c330b9a766a5fa0c7005ab3e86b750d8_amd64 |
| Red Hat | openshift4/ose-docker-registry@sha256:c713c3899087a9fa30e3a44aefcf0b2569c759c6ce991e7ee6fdb4918dd0346b_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cluster-samples-operator@sha256:ccf41a7239b1f5949daa9864d610faa121343b595ac3b3222c8a4f17ac2b76ad_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-samples-operator@sha256:ccf41a7239b1f5949daa9864d610faa121343b595ac3b3222c8a4f17ac2b76ad_amd64 |
| Red Hat | openshift4/ose-csi-livenessprobe@sha256:8ed5ae45c8e017eb773d6c3e174b748dabb53313ececd371656c9fe4fdfbf4df_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-csi-livenessprobe@sha256:8ed5ae45c8e017eb773d6c3e174b748dabb53313ececd371656c9fe4fdfbf4df_s390x |
| Red Hat | openshift4/ose-cluster-storage-operator@sha256:1f91a6d092207942064c2c362202a2c0d09854f2cc4102bea82e955b641cbc75_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-storage-operator@sha256:1f91a6d092207942064c2c362202a2c0d09854f2cc4102bea82e955b641cbc75_ppc64le |
| Red Hat | openshift4/ose-gcp-pd-csi-driver-operator-rhel8@sha256:907b6e5123723642c6685297763e5b5cefbc6e69ba62d139723f3a91436ecb88_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-gcp-pd-csi-driver-operator-rhel8@sha256:907b6e5123723642c6685297763e5b5cefbc6e69ba62d139723f3a91436ecb88_amd64 |
| Red Hat | openshift4/ose-prometheus-config-reloader@sha256:cc0b366a4272e8e639dd4649809ea09c8c0672d02f6727a557fbc41e9acd7013_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
…and 369 more
Timeline
- Apr 26, 2021 CVE Published
- Mar 26, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:1225 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1921650 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1927321 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1932113 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1936544 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1936719 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1941212 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1941993 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1942843 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1943316 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1947122 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1947909 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1948267 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1948938 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1949024 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1949239 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1225.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3121 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3121 advisory
…and 1 more