VDB
RHSA-2021:3598
RHSA-2021:3598
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in Go. The LookupCNAME, LookupSRV, LookupMX, LookupNS, and LookupAddr functions in the net package and methods on the Resolver type, may return arbitrary values retrieved from DNS, allowing injection of unexpected contents. The highest threat from this vulnerability is to integrity.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | container-native-virtualization/vm-import-operator-rhel8@sha256:ec39e0dc1c3d6c0912b1da5b9dc36682a5a702cd64978ec6d0b34651942944ca_amd64 as a component of CNV 4.8 for RHEL 8 | container-native-virtualization/vm-import-operator-rhel8@sha256:ec39e0dc1c3d6c0912b1da5b9dc36682a5a702cd64978ec6d0b34651942944ca_amd64 |
| Red Hat | container-native-virtualization/vm-import-operator-rhel8@sha256:ec39e0dc1c3d6c0912b1da5b9dc36682a5a702cd64978ec6d0b34651942944ca_amd64 as a component of CNV 4.8 for RHEL 8 | container-native-virtualization/vm-import-operator-rhel8@sha256:ec39e0dc1c3d6c0912b1da5b9dc36682a5a702cd64978ec6d0b34651942944ca_amd64, * |
Timeline
- Sep 21, 2021 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 CVE Updated
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1957791 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1972819 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1982143 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1990065 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1998983 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2000021 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2001038 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2001069 issue
- https://access.redhat.com/security/cve/CVE-2021-33197 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-33197 advisory
- https://access.redhat.com/security/cve/CVE-2021-33198 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-33198 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-34558 advisory
- https://golang.org/doc/devel/release#go1.15.minor advisory
- https://access.redhat.com/errata/RHSA-2021:3598 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1989570 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1989575 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1991460 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1993122 issue
…and 18 more