VDB
RHSA-2021%3A4582
RHSA-2021%3A4582
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in golang. A panic can be triggered by an attacker in a privileged network position without access to the server certificate's private key, as long as a trusted ECDSA or Ed25519 certificate for the server exists (or can be issued), or the client is configured with Config.InsecureSkipVerify. Clients that disable all TLS_RSA cipher suites (that is, TLS 1.0–1.2 cipher suites without ECDHE), as well as TLS 1.3-only clients, are unaffected.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | stf/smart-gateway-operator-bundle@sha256:f2105fb56eab3cf34f3012932ac74674743037797c7f0022a46b550d975e2605_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8 | stf/smart-gateway-operator-bundle@sha256:f2105fb56eab3cf34f3012932ac74674743037797c7f0022a46b550d975e2605_amd64 |
| Red Hat | stf/service-telemetry-operator-bundle@sha256:3aa38a05aa77bdac184c57f3152b56a9d43447dc086fb8d1388bf50f451d0947_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8 | * |
| Red Hat | stf/service-telemetry-rhel8-operator@sha256:26aada4cf2ee8427a482d23a26ac735a4141e885e04381e3eea0f417ddb7002a_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8 | * |
| Red Hat | stf/sg-core-rhel8@sha256:4ab99a587b957ec36ef14738abff0608e8bf14d18c771c6a405fdf003065b1fe_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8 | * |
| Red Hat | stf/smart-gateway-rhel8-operator@sha256:2f3d0901349c9e57c6084d4e5fa1407cd882d6c56163c69b54bbf69bdc919bdc_amd64 as a component of Service Telemetry Framework 1.3 for RHEL 8 | stf/smart-gateway-rhel8-operator@sha256:2f3d0901349c9e57c6084d4e5fa1407cd882d6c56163c69b54bbf69bdc919bdc_amd64 |
Timeline
- Nov 10, 2021 CVE Published
- Mar 27, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:4582 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1959166 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1983596 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2011603 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2013268 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4582.json advisory
- https://access.redhat.com/security/cve/CVE-2021-34558 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-34558 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-34558 advisory
- https://golang.org/doc/devel/release#go1.15.minor advisory
- https://golang.org/doc/devel/release#go1.16.minor advisory