VDB

RHSA-2021%3A3748

RHSA-2021%3A3748 PUBLISHED CVSS 6.5 MEDIUM

A flaw detected in golang: crypto/elliptic, in which P-224 keys as generated can return incorrect inputs, reducing the strength of the cryptography. The highest threat from this vulnerability is confidentiality and integrity.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Red Hatrhgs3/rhgs-volmanager-rhel7@sha256:e82d5d88395a3ac3577804b5ac1c6a5bbbfe49eb224ffe9acd8996442bdc4972_amd64 as a component of Red Hat Gluster Storage Server 3.5 on RHEL-7rhgs3/rhgs-volmanager-rhel7@sha256:e82d5d88395a3ac3577804b5ac1c6a5bbbfe49eb224ffe9acd8996442bdc4972_amd64
Red Hatrhgs3/rhgs-gluster-block-prov-rhel7@sha256:37acd6bfc91127d8b50447e7db190fbaea5241b031c8829e4faeac44c3fb6648_amd64 as a component of Red Hat Gluster Storage Server 3.5 on RHEL-7rhgs3/rhgs-gluster-block-prov-rhel7@sha256:37acd6bfc91127d8b50447e7db190fbaea5241b031c8829e4faeac44c3fb6648_amd64
Red Hatrhgs3/rhgs-server-rhel7@sha256:b8b6c480ad5d74ffd872abf3d741bff2d4d196f7dc01856fb67959f48407c820_amd64 as a component of Red Hat Gluster Storage Server 3.5 on RHEL-7rhgs3/rhgs-server-rhel7@sha256:b8b6c480ad5d74ffd872abf3d741bff2d4d196f7dc01856fb67959f48407c820_amd64

Timeline

  • Oct 7, 2021 CVE Published
  • Mar 19, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›