VDB

RHSA-2021%3A4582

RHSA-2021%3A4582 PUBLISHED CVSS 6.5 MEDIUM

A flaw was found in golang. A panic can be triggered by an attacker in a privileged network position without access to the server certificate's private key, as long as a trusted ECDSA or Ed25519 certificate for the server exists (or can be issued), or the client is configured with Config.InsecureSkipVerify. Clients that disable all TLS_RSA cipher suites (that is, TLS 1.0–1.2 cipher suites without ECDHE), as well as TLS 1.3-only clients, are unaffected.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatstf/smart-gateway-operator-bundle@sha256:f2105fb56eab3cf34f3012932ac74674743037797c7f0022a46b550d975e2605_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8stf/smart-gateway-operator-bundle@sha256:f2105fb56eab3cf34f3012932ac74674743037797c7f0022a46b550d975e2605_amd64
Red Hatstf/service-telemetry-operator-bundle@sha256:3aa38a05aa77bdac184c57f3152b56a9d43447dc086fb8d1388bf50f451d0947_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8*
Red Hatstf/service-telemetry-rhel8-operator@sha256:26aada4cf2ee8427a482d23a26ac735a4141e885e04381e3eea0f417ddb7002a_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8*
Red Hatstf/sg-core-rhel8@sha256:4ab99a587b957ec36ef14738abff0608e8bf14d18c771c6a405fdf003065b1fe_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8*
Red Hatstf/smart-gateway-rhel8-operator@sha256:2f3d0901349c9e57c6084d4e5fa1407cd882d6c56163c69b54bbf69bdc919bdc_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8stf/smart-gateway-rhel8-operator@sha256:2f3d0901349c9e57c6084d4e5fa1407cd882d6c56163c69b54bbf69bdc919bdc_amd64

Timeline

  • Nov 10, 2021 CVE Published
  • Mar 27, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›