VDB
RHSA-2021%3A2977
RHSA-2021%3A2977
PUBLISHED
CVSS 8.600000381469727 HIGH
A flaw was found in github.com/gogo/protobuf before 1.3.2 that allows an out-of-bounds access when unmarshalling certain protobuf objects. This flaw allows a remote attacker to send crafted protobuf messages, causing panic and resulting in a denial of service. The highest threat from this vulnerability is to availability.
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-baremetal-runtimecfg-rhel8@sha256:8f316e9bcf68ca9a6e3a443b0cbdfbdd34fe5cb146760f5d4032ce8830d6c576_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-baremetal-runtimecfg-rhel8@sha256:8f316e9bcf68ca9a6e3a443b0cbdfbdd34fe5cb146760f5d4032ce8830d6c576_s390x |
| Red Hat | openshift4/ose-must-gather@sha256:2ad77b5a846e23e6b64f099913f722cadc526083e6439682229d67d325900b51_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-must-gather@sha256:2ad77b5a846e23e6b64f099913f722cadc526083e6439682229d67d325900b51_ppc64le |
| Red Hat | openshift4/ose-operator-marketplace@sha256:f1f1a769f1b29e59e552019519058a40c18a2966570d104d7f0cea083daaff15_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-thanos-rhel8@sha256:f33e174a219ad1bb6ba6565e2317d1de2fb4ae5a6b462079c14d878c26e2da46_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-thanos-rhel8@sha256:f33e174a219ad1bb6ba6565e2317d1de2fb4ae5a6b462079c14d878c26e2da46_amd64 |
| Red Hat | openshift4/ose-cluster-kube-apiserver-operator@sha256:50bf9543ecc46f638aa88260be18d543351abe2d18c722f084572c1cb3c905a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-kube-apiserver-operator@sha256:50bf9543ecc46f638aa88260be18d543351abe2d18c722f084572c1cb3c905a8_ppc64le |
| Red Hat | openshift4/ose-prometheus-config-reloader@sha256:90017616f2eaf9c91ef3218ae46e0a2e7d81b339b0481eab57b234cb8833862b_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-prometheus-config-reloader@sha256:90017616f2eaf9c91ef3218ae46e0a2e7d81b339b0481eab57b234cb8833862b_ppc64le |
| Red Hat | openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator@sha256:b06610c078f8f6c3b8f3aa7906f6bf25b3a629bc3c532d4d88a51ae5c29fc6da_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-kube-storage-version-migrator-rhel8-operator@sha256:b06610c078f8f6c3b8f3aa7906f6bf25b3a629bc3c532d4d88a51ae5c29fc6da_ppc64le |
| Red Hat | openshift4/ose-k8s-prometheus-adapter@sha256:941f4ed69e5a7911f31c2ffdddbe59fa6a424f63a57d22cf180831fb0610ab61_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-k8s-prometheus-adapter@sha256:941f4ed69e5a7911f31c2ffdddbe59fa6a424f63a57d22cf180831fb0610ab61_ppc64le |
| Red Hat | openshift4/ose-haproxy-router@sha256:05bc43dcf7ecc792de72f9decc0f6b4dbdc4d08445c72b9b1466509c1b13693b_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-haproxy-router@sha256:05bc43dcf7ecc792de72f9decc0f6b4dbdc4d08445c72b9b1466509c1b13693b_s390x |
| Red Hat | openshift4/ose-csi-external-resizer@sha256:b95d52eda40b175fe19d08de6449264df8595c662cf7a72889992eb1471cf46a_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-csi-external-resizer@sha256:b95d52eda40b175fe19d08de6449264df8595c662cf7a72889992eb1471cf46a_ppc64le |
| Red Hat | openshift4/ose-multus-route-override-cni-rhel8@sha256:5e4371bb1a93d357d0e58b595586ac5e5ed1959cc3dd94d778dcae2f024aa571_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cluster-openshift-apiserver-operator@sha256:bd2688fb0c2b0ee340309041a47e6dcf9e9f6436d942a71a6ef846e5ed758ba3_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-openshift-apiserver-operator@sha256:bd2688fb0c2b0ee340309041a47e6dcf9e9f6436d942a71a6ef846e5ed758ba3_ppc64le |
| Red Hat | openshift4/ose-etcd@sha256:093e549602fd6a41a38bb0a4ecd5d40589ee2f7cf3bd46788549d3d897e8bfaf_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-etcd@sha256:093e549602fd6a41a38bb0a4ecd5d40589ee2f7cf3bd46788549d3d897e8bfaf_amd64 |
| Red Hat | openshift4/ose-coredns@sha256:deb9f69f409ba9038a8b491565c4d2094b351e738395ae644aa0eaaec90c7c4f_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-csi-external-snapshotter@sha256:b0194b58dace6e087d8694f4dba85105603bfff79e2ac815ad6246471b643404_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-csi-external-snapshotter@sha256:b0194b58dace6e087d8694f4dba85105603bfff79e2ac815ad6246471b643404_ppc64le |
| Red Hat | openshift4/ose-cluster-update-keys@sha256:14530a13c1c8df9f928607c19b91429f3f8a59bfad8e731e473394febc373a6a_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-update-keys@sha256:14530a13c1c8df9f928607c19b91429f3f8a59bfad8e731e473394febc373a6a_s390x |
| Red Hat | openshift4/ose-cloud-credential-operator@sha256:bb64d1548ee84d46b69767eadceeea7b6f2087aaed60c4d9f4d59cf53bf848c8_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cloud-credential-operator@sha256:bb64d1548ee84d46b69767eadceeea7b6f2087aaed60c4d9f4d59cf53bf848c8_s390x |
| Red Hat | openshift4/ose-ironic-rhel8@sha256:9cf57f8b31c2e4dd40d503d96a3ae2916b3e552dc1c73ba11628a30285ee9bd7_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-ironic-rhel8@sha256:9cf57f8b31c2e4dd40d503d96a3ae2916b3e552dc1c73ba11628a30285ee9bd7_ppc64le |
| Red Hat | openshift4/ose-machine-config-operator@sha256:0931af92887059a0a3ed1b7a6079f83203fa8d06362fa4bc7c1f5cc3bea364b6_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-machine-config-operator@sha256:0931af92887059a0a3ed1b7a6079f83203fa8d06362fa4bc7c1f5cc3bea364b6_ppc64le |
| Red Hat | openshift4/ose-prometheus@sha256:8cd6786c2173904ed0bb0aa180f047748bc1c24e7453d72c8b04f054861dfcca_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-prometheus@sha256:8cd6786c2173904ed0bb0aa180f047748bc1c24e7453d72c8b04f054861dfcca_s390x |
…and 372 more
Timeline
- Aug 11, 2021 CVE Published
- Mar 26, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:2977 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1921650 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1933726 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1962036 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1970166 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1975469 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1977432 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1982929 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1985516 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1985545 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1985546 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1986591 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2977.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3121 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3121 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3121 advisory