VDB

RHSA-2021%3A1227

RHSA-2021%3A1227 PUBLISHED CVSS 8.600000381469727 HIGH

A flaw was found in github.com/gogo/protobuf before 1.3.2 that allows an out-of-bounds access when unmarshalling certain protobuf objects. This flaw allows a remote attacker to send crafted protobuf messages, causing panic and resulting in a denial of service. The highest threat from this vulnerability is to availability.

Risk Scores

CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:15b6f02ac30d0164a2864e5b67fb795f71ea058df93edec60deebacaa27b0043_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:15b6f02ac30d0164a2864e5b67fb795f71ea058df93edec60deebacaa27b0043_amd64
Red Hatopenshift4/ose-sriov-infiniband-cni@sha256:94464c52c49a6056a75a637a7f7b24c2c5f4172c5784dcd464b797bab29cfa1e_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-infiniband-cni@sha256:94464c52c49a6056a75a637a7f7b24c2c5f4172c5784dcd464b797bab29cfa1e_amd64
Red Hatopenshift4/ose-ptp-operator@sha256:c540a8e5cd8cdf98af525c04aebf74b80073df7f6a847d9b9c9760a48d00074d_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-ptp-operator@sha256:c540a8e5cd8cdf98af525c04aebf74b80073df7f6a847d9b9c9760a48d00074d_s390x
Red Hatopenshift4/ptp-must-gather-rhel8@sha256:f888320b44ad896b24107a1e0580b6e14f233250889af8a4b5874d5d5842892b_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ptp-must-gather-rhel8@sha256:f888320b44ad896b24107a1e0580b6e14f233250889af8a4b5874d5d5842892b_s390x
Red Hatopenshift4/ose-sriov-network-operator@sha256:f5120d3e089e90bcdf784515bc6d2a807d51ec4a391488623072694ad16cec07_s390x as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:3db01df54c18ad139f55b9874dab16f19585f106d862a300de8131d9094dadd1_ppc64le as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-local-storage-mustgather-rhel8@sha256:6ed4294ca3e9415d85fe448da084699b0140e75a73374edc8b933df6a8b3f4de_amd64 as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-sriov-network-device-plugin@sha256:c8ee19c41af8db6dd3d9f7e2ebffeb857e48234940ada4c0e2d0d2f04c53698f_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-network-device-plugin@sha256:c8ee19c41af8db6dd3d9f7e2ebffeb857e48234940ada4c0e2d0d2f04c53698f_ppc64le
Red Hatopenshift4/network-tools-rhel8@sha256:84e08830a2d8740bd7ebafb19333e644244bc39c341185fc2599483eb53b1462_amd64 as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-sriov-dp-admission-controller@sha256:858bcd10c53def2d93350e51763e83c1cf20daa58c6174e7a47de424ae1e0eb7_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-dp-admission-controller@sha256:858bcd10c53def2d93350e51763e83c1cf20daa58c6174e7a47de424ae1e0eb7_ppc64le
Red Hatopenshift4/ose-ptp-operator@sha256:f5f0347d3455b2e28888fcaa5e7cbb13474ed7ab82fc870ec1001eba0bfbf142_amd64 as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-sriov-dp-admission-controller@sha256:bf1abf1fc9f5c96220fc42668f47ea0ad55e412c1383a2111d3684a7e5d62fa1_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-dp-admission-controller@sha256:bf1abf1fc9f5c96220fc42668f47ea0ad55e412c1383a2111d3684a7e5d62fa1_amd64
Red Hatopenshift4/ose-leader-elector-rhel8@sha256:fbecfc4e4358f57a437c7050bd6fb52b4760ce938b08a87cb5bcd03ff5cfe828_s390x as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-leader-elector-rhel8@sha256:fbecfc4e4358f57a437c7050bd6fb52b4760ce938b08a87cb5bcd03ff5cfe828_s390x
Red Hatopenshift4/ose-local-storage-diskmaker@sha256:6d0fbb2485401f4a5af63c2c66d429254515ee35a5e53112cb26bbf19a078b4e_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-local-storage-diskmaker@sha256:6d0fbb2485401f4a5af63c2c66d429254515ee35a5e53112cb26bbf19a078b4e_amd64
Red Hatopenshift4/ose-sriov-network-webhook@sha256:abb18e327cb63dc97885442a08b2cdbbcea034e72b05f672eb8a37d6352953f8_amd64 as a component of Red Hat OpenShift Container Platform 4.7*
Red Hatopenshift4/ose-ptp@sha256:fe0df871cc9b9d36adef3d58aa683ce8a93c30ee7478a22df0e9a2450d59d0ff_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-ptp@sha256:fe0df871cc9b9d36adef3d58aa683ce8a93c30ee7478a22df0e9a2450d59d0ff_amd64
Red Hatopenshift4/ose-operator-sdk-rhel8@sha256:9f70ecd332b702f5b70996126e348365fc8b427d57160b3151efbbc199e30d89_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-operator-sdk-rhel8@sha256:9f70ecd332b702f5b70996126e348365fc8b427d57160b3151efbbc199e30d89_amd64
Red Hatopenshift4/ose-sriov-cni@sha256:a1f01f5fe3fe3d8ceca80e13bda00a7547f2c742bbffc5c0599a2a5e0a1610b0_amd64 as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-sriov-cni@sha256:a1f01f5fe3fe3d8ceca80e13bda00a7547f2c742bbffc5c0599a2a5e0a1610b0_amd64
Red Hatopenshift4/ose-local-storage-static-provisioner@sha256:6c40f9a39faadd6b7481134678a24d289d10660dd91203d3ce49c935cb491f19_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-local-storage-static-provisioner@sha256:6c40f9a39faadd6b7481134678a24d289d10660dd91203d3ce49c935cb491f19_ppc64le
Red Hatopenshift4/ose-ptp@sha256:04a83c2c9299588c6403f2e211756b0cc2a59f794b2c1ea4d015143c610b60b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.7openshift4/ose-ptp@sha256:04a83c2c9299588c6403f2e211756b0cc2a59f794b2c1ea4d015143c610b60b1_ppc64le

…and 106 more

Timeline

  • Apr 26, 2021 CVE Published
  • Mar 26, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›