VDB
RHSA-2021%3A4725
RHSA-2021%3A4725
PUBLISHED
CVSS 7.300000190734863 HIGH
A flaw was found in golang. Extraneous zero characters at the beginning of an IP address octet are not properly considered which could allow an attacker to bypass IP-based access controls. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | container-native-virtualization/vm-import-controller-rhel8@sha256:be60d10cd7bc87227136534878dc750f59da0a97eb2cc74f331e80e681feb098_amd64 as a component of CNV 2.6 for RHEL 8 | container-native-virtualization/vm-import-controller-rhel8@sha256:be60d10cd7bc87227136534878dc750f59da0a97eb2cc74f331e80e681feb098_amd64 |
| Red Hat | container-native-virtualization/vm-import-controller@sha256:be60d10cd7bc87227136534878dc750f59da0a97eb2cc74f331e80e681feb098_amd64 as a component of CNV 2.6 for RHEL 8 | * |
| Red Hat | container-native-virtualization/kubevirt-cpu-model-nfd-plugin@sha256:1c1628b639e26d05faf413c775d22d4a0ddd51d033473f740b2741b3d81e1716_amd64 as a component of CNV 2.6 for RHEL 8 | container-native-virtualization/kubevirt-cpu-model-nfd-plugin@sha256:1c1628b639e26d05faf413c775d22d4a0ddd51d033473f740b2741b3d81e1716_amd64 |
| Red Hat | container-native-virtualization/kubevirt-cpu-node-labeller@sha256:5888aa247f7e7a1e1e169fc224854527fa314e617d567c4fc6a36666ef783218_amd64 as a component of CNV 2.6 for RHEL 8 | * |
| Red Hat | container-native-virtualization/kubevirt-kvm-info-nfd-plugin@sha256:c4bf7b19fa46e3ce2e43051a9b108662f0061325ab417aaca71b00c3821910eb_amd64 as a component of CNV 2.6 for RHEL 8 | container-native-virtualization/kubevirt-kvm-info-nfd-plugin@sha256:c4bf7b19fa46e3ce2e43051a9b108662f0061325ab417aaca71b00c3821910eb_amd64 |
Timeline
- Nov 17, 2021 CVE Published
- Apr 29, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:4725 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1983596 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1992006 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1998844 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2008522 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2010334 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2012328 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2013494 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4725.json advisory
- https://access.redhat.com/security/cve/CVE-2021-29923 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-29923 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-29923 advisory
- https://sick.codes/sick-2021-016/ advisory
- https://access.redhat.com/security/cve/CVE-2021-34558 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-34558 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-34558 advisory
- https://golang.org/doc/devel/release#go1.15.minor advisory
- https://golang.org/doc/devel/release#go1.16.minor advisory