VDB
RHSA-2021%3A1552
RHSA-2021%3A1552
PUBLISHED
CVSS 8.600000381469727 HIGH
A flaw was found in github.com/gogo/protobuf before 1.3.2 that allows an out-of-bounds access when unmarshalling certain protobuf objects. This flaw allows a remote attacker to send crafted protobuf messages, causing panic and resulting in a denial of service. The highest threat from this vulnerability is to availability.
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:63bff9b5506263394129b06c3eb7573fc7bc66bd888d46997adde8a0175c9347_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:63bff9b5506263394129b06c3eb7573fc7bc66bd888d46997adde8a0175c9347_amd64 |
| Red Hat | openshift4/network-tools-rhel8@sha256:9e302c5584f6180f79b09882948c30a6b3b265ac3b44f7806b2c6ddee41fd584_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:3aaf6fcbb2ecdf130a2f3d13cfadb4a631019690b85a1f5eb42d341f2c2e8035_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:eabf7c557362188d0067db3a34a646c52efc337f831abdd3c1b679cef24a0c39_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-sriov-infiniband-cni@sha256:dde1aa450590a1172a39cfe9d829b1380192291070716d1f195fbe36d7585846_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-ansible-operator@sha256:494273ae3456a8e7d2ce93be8c8d1440a9a8bdf9d7546d871c2335088dd1bf2c_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cluster-kube-descheduler-operator@sha256:3806a0ad25af8571f4ab0bd7208ea0de6b4c6eff3e566d28f128ad4e35c47d45_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-kube-descheduler-operator@sha256:3806a0ad25af8571f4ab0bd7208ea0de6b4c6eff3e566d28f128ad4e35c47d45_ppc64le |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:33e40f5366b349e44885b40dfb1b0e3e625b5a2adb37de719fb11dac2ec62fc0_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-operator@sha256:33e40f5366b349e44885b40dfb1b0e3e625b5a2adb37de719fb11dac2ec62fc0_s390x |
| Red Hat | openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:3806a0ad25af8571f4ab0bd7208ea0de6b4c6eff3e566d28f128ad4e35c47d45_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cluster-kube-descheduler-operator@sha256:3806a0ad25af8571f4ab0bd7208ea0de6b4c6eff3e566d28f128ad4e35c47d45_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-kube-descheduler-operator@sha256:3806a0ad25af8571f4ab0bd7208ea0de6b4c6eff3e566d28f128ad4e35c47d45_ppc64le |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:7ce3db75dbc8c1a912ae7c40c09596ff0d80b8c896b475a230e5cd1f1ff3d6fa_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-operator@sha256:7ce3db75dbc8c1a912ae7c40c09596ff0d80b8c896b475a230e5cd1f1ff3d6fa_ppc64le |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:eabf7c557362188d0067db3a34a646c52efc337f831abdd3c1b679cef24a0c39_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-service-idler-rhel8@sha256:d59728003550000f3f26437009bb29bc3d310d7b2c941d9a043063436b5a37e9_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-service-idler-rhel8@sha256:d59728003550000f3f26437009bb29bc3d310d7b2c941d9a043063436b5a37e9_ppc64le |
| Red Hat | openshift4/ose-sriov-dp-admission-controller@sha256:7abbcf7c0275b08d5b00178da0b58a87bc9ce493fb9b115be521d8037de9c343_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-dp-admission-controller@sha256:7abbcf7c0275b08d5b00178da0b58a87bc9ce493fb9b115be521d8037de9c343_ppc64le |
| Red Hat | openshift4/ose-service-idler-rhel8@sha256:d59728003550000f3f26437009bb29bc3d310d7b2c941d9a043063436b5a37e9_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-service-idler-rhel8@sha256:d59728003550000f3f26437009bb29bc3d310d7b2c941d9a043063436b5a37e9_ppc64le |
| Red Hat | openshift4/ose-ansible-operator@sha256:ad7db49784e4d0cd586d693f8b2405cc6445ae81817d37ce0b42434214a5c3e8_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-ansible-operator@sha256:ad7db49784e4d0cd586d693f8b2405cc6445ae81817d37ce0b42434214a5c3e8_s390x |
| Red Hat | openshift4/ose-sriov-network-operator@sha256:33e40f5366b349e44885b40dfb1b0e3e625b5a2adb37de719fb11dac2ec62fc0_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-network-operator@sha256:33e40f5366b349e44885b40dfb1b0e3e625b5a2adb37de719fb11dac2ec62fc0_s390x |
| Red Hat | openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:3806a0ad25af8571f4ab0bd7208ea0de6b4c6eff3e566d28f128ad4e35c47d45_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:3806a0ad25af8571f4ab0bd7208ea0de6b4c6eff3e566d28f128ad4e35c47d45_ppc64le |
| Red Hat | openshift4/ose-sriov-dp-admission-controller@sha256:332b1a7d738d6eb12d44ab2703678740b14b9985dd6ade80176c827b694e821a_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-sriov-dp-admission-controller@sha256:332b1a7d738d6eb12d44ab2703678740b14b9985dd6ade80176c827b694e821a_amd64 |
| Red Hat | openshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:eb3b70cf52702e45304d92e029ce8dc7ffeb2c52c149581a81b44461bf05eca0_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:eb3b70cf52702e45304d92e029ce8dc7ffeb2c52c149581a81b44461bf05eca0_s390x |
…and 44 more
Timeline
- May 19, 2021 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2021:1552 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1919391 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1921650 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1940584 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1959661 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1552.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3121 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3121 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3121 advisory
- https://access.redhat.com/security/cve/CVE-2021-20206 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-20206 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-20206 advisory