VDB
RHSA-2021%3A1561
RHSA-2021%3A1561
PUBLISHED
CVSS 7.5 HIGH
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker could use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-installer-artifacts@sha256:bd2f3f2be47fbff5200920ae6bdd9069de5b3da6c4b4ba094cf5312e3e72f6ca_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-installer-artifacts@sha256:bd2f3f2be47fbff5200920ae6bdd9069de5b3da6c4b4ba094cf5312e3e72f6ca_s390x |
| Red Hat | openshift4/ose-kuryr-cni-rhel8@sha256:cfc1e94a4011ee39e98f3b285526273eae44ee1e8dbafdb2f92c028dbeab6750_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-kuryr-cni-rhel8@sha256:cfc1e94a4011ee39e98f3b285526273eae44ee1e8dbafdb2f92c028dbeab6750_ppc64le |
| Red Hat | openshift4/ose-installer-artifacts@sha256:21b51344f57eeae2a2974ed4936f8315629aeea5fcc7fd22d5044a1f401db903_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-machine-api-operator@sha256:ec40bdf083648e23ad3b68c4fe21b18d2208579f21b8ff6097b77a66b9afb738_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-machine-api-operator@sha256:ec40bdf083648e23ad3b68c4fe21b18d2208579f21b8ff6097b77a66b9afb738_s390x |
| Red Hat | openshift4/ose-installer@sha256:485dcaa163b2a475dadee71102df6dc4b0687805a3112082a6c3477fa0b1f183_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-operator-lifecycle-manager@sha256:9f38edba8d7a0ec58cb08ce95c8dd0632b0a95d8ef243720dfeb24180d2e35bc_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-operator-lifecycle-manager@sha256:9f38edba8d7a0ec58cb08ce95c8dd0632b0a95d8ef243720dfeb24180d2e35bc_ppc64le |
| Red Hat | openshift4/ose-hyperkube@sha256:8def23bb6abba45101c5773a720432cdc61ba73bb8254d9a7356bd63838c26e8_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-hyperkube@sha256:8def23bb6abba45101c5773a720432cdc61ba73bb8254d9a7356bd63838c26e8_s390x |
| Red Hat | openshift4/ose-hello-openshift-rhel8@sha256:84d44434d85b8f26a410f56a4ccc4a8a4a9bad232eb1690f31391c2365103873_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-hello-openshift-rhel8@sha256:84d44434d85b8f26a410f56a4ccc4a8a4a9bad232eb1690f31391c2365103873_s390x |
| Red Hat | openshift4/ose-ovn-kubernetes@sha256:1cfe5321c0dee7fc2341f553ed5ca62732fe89a13924d4ef3194c5723382abd8_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-ovn-kubernetes@sha256:1cfe5321c0dee7fc2341f553ed5ca62732fe89a13924d4ef3194c5723382abd8_s390x |
| Red Hat | openshift4/ose-ovn-kubernetes@sha256:4a300837a1710ff77bc40732893fd6f5f8d50ca2a73b53ea380f1890a4f27535_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-ovn-kubernetes@sha256:4a300837a1710ff77bc40732893fd6f5f8d50ca2a73b53ea380f1890a4f27535_ppc64le |
| Red Hat | openshift4/ose-ironic-rhel8@sha256:01d2bb71a5f53e5e29a8c468ea26939ef2f35117aa84fc78be41093f87f097e4_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cluster-monitoring-operator@sha256:006f144200bea0926bf192c55a7b22f076a8ca6d8e316f059302dc08b07ae817_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-monitoring-operator@sha256:006f144200bea0926bf192c55a7b22f076a8ca6d8e316f059302dc08b07ae817_ppc64le |
| Red Hat | openshift4/ose-baremetal-installer-rhel8@sha256:914dd3b94d5c4dcab60d65d19447b7fc35a189ce08b13986a48d56825c274286_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-baremetal-installer-rhel8@sha256:914dd3b94d5c4dcab60d65d19447b7fc35a189ce08b13986a48d56825c274286_amd64 |
| Red Hat | openshift4/ose-cluster-authentication-operator@sha256:789f7d1d0b0d685641b3d9292aedcdc29403ad59537b2938aebdd3537f468328_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-authentication-operator@sha256:789f7d1d0b0d685641b3d9292aedcdc29403ad59537b2938aebdd3537f468328_amd64 |
| Red Hat | openshift4/ose-operator-lifecycle-manager@sha256:9673487dcd4312b3bf8c467b5a238c5486a037545bb6b4c93cbf5f67565c0106_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-operator-lifecycle-manager@sha256:9673487dcd4312b3bf8c467b5a238c5486a037545bb6b4c93cbf5f67565c0106_amd64 |
| Red Hat | openshift4/ose-cloud-credential-operator@sha256:d3aa81268b88e7d42dd247c4e0ee528d214ca0231c3832423e76610d0f070ca3_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cloud-credential-operator@sha256:d3aa81268b88e7d42dd247c4e0ee528d214ca0231c3832423e76610d0f070ca3_amd64 |
| Red Hat | openshift4/ose-cloud-credential-operator@sha256:31541bf48ac631a67b6e1d0b37aca0d63f6aeb3fdc67700616aaaedecad9eeb1_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-operator-lifecycle-manager@sha256:f880d91d558902e49a4663498251b3493b75caa587479af45bdf57a5005c4410_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-operator-lifecycle-manager@sha256:f880d91d558902e49a4663498251b3493b75caa587479af45bdf57a5005c4410_s390x |
| Red Hat | openshift4/ose-tests@sha256:eb825f942f04d4b9643c6f0b59f151541034b8affcf5ff71671ae3434ccd7d04_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-tests@sha256:eb825f942f04d4b9643c6f0b59f151541034b8affcf5ff71671ae3434ccd7d04_amd64 |
| Red Hat | openshift4/ose-hyperkube@sha256:a282af0f5a34a611dfe987a1a9a60d7c42c2512a3a83828c4e340214681c39e7_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-hyperkube@sha256:a282af0f5a34a611dfe987a1a9a60d7c42c2512a3a83828c4e340214681c39e7_amd64 |
…and 28 more
Timeline
- May 24, 2021 CVE Published
- Apr 30, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:1561 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1902111 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1926577 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1942141 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1942488 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1943500 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1947097 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1948396 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1950261 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1951726 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1952149 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1955449 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1955462 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1955469 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1955689 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1955883 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1956270 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1956797 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1958797 issue
…and 10 more