VDB
RHSA-2021%3A3748
RHSA-2021%3A3748
PUBLISHED
CVSS 6.5 MEDIUM
A flaw detected in golang: crypto/elliptic, in which P-224 keys as generated can return incorrect inputs, reducing the strength of the cryptography. The highest threat from this vulnerability is confidentiality and integrity.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhgs3/rhgs-volmanager-rhel7@sha256:e82d5d88395a3ac3577804b5ac1c6a5bbbfe49eb224ffe9acd8996442bdc4972_amd64 as a component of Red Hat Gluster Storage Server 3.5 on RHEL-7 | rhgs3/rhgs-volmanager-rhel7@sha256:e82d5d88395a3ac3577804b5ac1c6a5bbbfe49eb224ffe9acd8996442bdc4972_amd64 |
| Red Hat | rhgs3/rhgs-gluster-block-prov-rhel7@sha256:37acd6bfc91127d8b50447e7db190fbaea5241b031c8829e4faeac44c3fb6648_amd64 as a component of Red Hat Gluster Storage Server 3.5 on RHEL-7 | rhgs3/rhgs-gluster-block-prov-rhel7@sha256:37acd6bfc91127d8b50447e7db190fbaea5241b031c8829e4faeac44c3fb6648_amd64 |
| Red Hat | rhgs3/rhgs-server-rhel7@sha256:b8b6c480ad5d74ffd872abf3d741bff2d4d196f7dc01856fb67959f48407c820_amd64 as a component of Red Hat Gluster Storage Server 3.5 on RHEL-7 | rhgs3/rhgs-server-rhel7@sha256:b8b6c480ad5d74ffd872abf3d741bff2d4d196f7dc01856fb67959f48407c820_amd64 |
Timeline
- Oct 7, 2021 CVE Published
- Mar 19, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:3748 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1918750 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1957321 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1958341 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1987163 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3748.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3114 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3114 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3114 advisory
- https://groups.google.com/g/golang-announce/c/mperVMGa98w advisory
- https://access.redhat.com/security/cve/CVE-2021-31525 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-31525 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-31525 advisory
- https://groups.google.com/g/golang-announce/c/cu9SP4eSXMc advisory