VDB
RHSA-2021%3A3303
RHSA-2021%3A3303
PUBLISHED
CVSS 8.600000381469727 HIGH
A flaw was found in github.com/gogo/protobuf before 1.3.2 that allows an out-of-bounds access when unmarshalling certain protobuf objects. This flaw allows a remote attacker to send crafted protobuf messages, causing panic and resulting in a denial of service. The highest threat from this vulnerability is to availability.
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-ovn-kubernetes@sha256:5a1d202ba457e34c2b3c6a1b7e4144e39800f1468cf1cb739d978977bec5637b_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-ovn-kubernetes@sha256:5a1d202ba457e34c2b3c6a1b7e4144e39800f1468cf1cb739d978977bec5637b_ppc64le |
| Red Hat | openshift4/ose-csi-external-provisioner@sha256:bf46f639014f11c814d275bd210275e5ba8163767279950056fe524220785b15_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-csi-external-provisioner@sha256:bf46f639014f11c814d275bd210275e5ba8163767279950056fe524220785b15_ppc64le |
| Red Hat | openshift4/ose-jenkins-agent-base@sha256:85f98c214f82607f501b05dc26f0692909a514a8640c5e304a7107d01f4a01b0_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-thanos-rhel8@sha256:3261c8a9bcef396722aeb90553d6f91b06640b8ae33a6bf43afcc7475795c45a_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-csi-external-resizer-rhel8@sha256:db548a800169bc76810ff7b9bca28ff1a156a9a969aab70528777d61b5101c7b_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-service-ca-operator@sha256:ba627156eb2e8cbd824dd74e0bfe14be6824962f33038e36b62c9874c3c72e9a_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-tools-rhel8@sha256:af6a12e407467cfe9222b7fb8cb55a496b6464a34757df3f1da73bf1dce9eb76_s390x as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-openstack-cinder-csi-driver-rhel8@sha256:5e02ee1bd744533150bc0039e024c7b02f9255a5a2164d8f09d2b96a31256cd8_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-telemeter@sha256:7b03dfa40ea05b2eb1ec3ca42e1058b52d4efedc8c6993cf703bea82f95342c8_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-telemeter@sha256:7b03dfa40ea05b2eb1ec3ca42e1058b52d4efedc8c6993cf703bea82f95342c8_ppc64le |
| Red Hat | openshift4/ose-csi-external-resizer@sha256:79db45c7ea226feceb285f2b31b5989678af985c1c067996d184948e61d7dce0_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-csi-external-resizer@sha256:79db45c7ea226feceb285f2b31b5989678af985c1c067996d184948e61d7dce0_amd64 |
| Red Hat | openshift4/ose-cluster-autoscaler-operator@sha256:7d741a8c85844aad899ec45cc3a5eb2af279fb2b76698a1a47fb53205a22caaa_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-autoscaler-operator@sha256:7d741a8c85844aad899ec45cc3a5eb2af279fb2b76698a1a47fb53205a22caaa_s390x |
| Red Hat | openshift4/ose-cluster-update-keys@sha256:f45b788e46012ad323a421022b56dd18658d74895ce9e2d6c94cc477684fde52_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-update-keys@sha256:f45b788e46012ad323a421022b56dd18658d74895ce9e2d6c94cc477684fde52_s390x |
| Red Hat | openshift4/ose-cluster-network-operator@sha256:51a41b6bbbde6b3d70a223e309d8231f8b2aaa748689177770b08644099f0749_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-network-operator@sha256:51a41b6bbbde6b3d70a223e309d8231f8b2aaa748689177770b08644099f0749_amd64 |
| Red Hat | openshift4/ose-gcp-machine-controllers-rhel8@sha256:7858bfe4db9bb82ca149229905926edaafa2063cc3904544a4407592837e83d8_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-cli@sha256:49b6a3899818c82e1b94b6a2beaa33312316daafaae74f92ef3f3ddb81e830e1_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cli@sha256:49b6a3899818c82e1b94b6a2beaa33312316daafaae74f92ef3f3ddb81e830e1_s390x |
| Red Hat | openshift4/ose-etcd@sha256:728f86a15e405862bb4fe511348a24d582a898ed4c5d930199cabd2e9a141e2a_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-etcd@sha256:728f86a15e405862bb4fe511348a24d582a898ed4c5d930199cabd2e9a141e2a_ppc64le |
| Red Hat | openshift4/ose-kube-storage-version-migrator-rhel8@sha256:d1d6ffcd6725ad17881c60c24e5ae6fd8b0e79da08675c5170d46955e54e96ef_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-kube-storage-version-migrator-rhel8@sha256:d1d6ffcd6725ad17881c60c24e5ae6fd8b0e79da08675c5170d46955e54e96ef_s390x |
| Red Hat | openshift4/ose-mdns-publisher-rhel8@sha256:b397be71010bdb712b253cb0e42a81810fb8ec8f30ce125d4f6f3d4c6f92c08f_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
| Red Hat | openshift4/ose-openshift-state-metrics-rhel8@sha256:fb59b2bdbaa84ad33be510db0215df3771cdeadde6fc26b7013127ec04fe2e30_s390x as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-openshift-state-metrics-rhel8@sha256:fb59b2bdbaa84ad33be510db0215df3771cdeadde6fc26b7013127ec04fe2e30_s390x |
| Red Hat | openshift4/ose-installer-artifacts@sha256:2091b27393b778d096ea6f84249981e53de02736703afba841294646d6f0fba0_ppc64le as a component of Red Hat OpenShift Container Platform 4.7 | openshift4/ose-installer-artifacts@sha256:2091b27393b778d096ea6f84249981e53de02736703afba841294646d6f0fba0_ppc64le |
…and 318 more
Timeline
- Sep 8, 2021 CVE Published
- Mar 26, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:3303 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1921650 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1960103 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1967359 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1972430 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1976242 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1994601 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1995199 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1995579 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1995910 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1996698 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1996846 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1997104 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1998996 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1998997 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1998998 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3303.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3121 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3121 advisory
…and 1 more