First published: Wed Jan 20 2021(Updated: )
An unspecified error with the P224() Curve implementation can generate incorrect outputs in Golang Go has an unknown impact and attack vector.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/golang-1.11 | 1.11.6-1+deb10u4 1.11.6-1+deb10u7 | |
debian/golang-1.15 | 1.15.15-1~deb11u4 | |
redhat/go | <1.15.7 | 1.15.7 |
redhat/go | <1.14.14 | 1.14.14 |
redhat/heketi | <0:10.4.0-2.el7 | 0:10.4.0-2.el7 |
redhat/openshift-serverless-clients | <0:0.20.0-6.el8 | 0:0.20.0-6.el8 |
redhat/openshift-serverless-clients | <0:0.20.0-7.el8 | 0:0.20.0-7.el8 |
redhat/grafana | <0:7.5.9-4.el8 | 0:7.5.9-4.el8 |
redhat/ignition | <0:2.6.0-7.rhaos4.6.git947598e.el8 | 0:2.6.0-7.rhaos4.6.git947598e.el8 |
redhat/openshift | <0:4.7.0-202103181538.p0.git.97109.7576cdc.el7 | 0:4.7.0-202103181538.p0.git.97109.7576cdc.el7 |
redhat/openshift-clients | <0:4.7.0-202103191426.p0.git.3953.f3a7513.el7 | 0:4.7.0-202103191426.p0.git.3953.f3a7513.el7 |
redhat/cri-o | <0:1.20.2-4.rhaos4.7.gitd5a999a.el8 | 0:1.20.2-4.rhaos4.7.gitd5a999a.el8 |
redhat/cri-tools | <0:1.20.0-2.el8 | 0:1.20.0-2.el8 |
redhat/runc | <0:1.0.0-95.rhaos4.8.gitcd80260.el8 | 0:1.0.0-95.rhaos4.8.gitcd80260.el8 |
redhat/golang-github-prometheus-promu | <0:0.5.0-3.git642a960.el8 | 0:0.5.0-3.git642a960.el8 |
redhat/ignition | <0:2.9.0-6.rhaos4.8.el8 | 0:2.9.0-6.rhaos4.8.el8 |
redhat/kubevirt | <0:4.9.0-287.el8 | 0:4.9.0-287.el8 |
Golang Go | <1.14.14 | |
Golang Go | >=1.15<1.15.7 | |
Fedoraproject Fedora | =33 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Netapp Cloud Insights Telegraf Agent | ||
Netapp Storagegrid | ||
IBM Cloud Pak for Security | <=1.10.0.0 - 1.10.11.0 | |
IBM QRadar Suite Software | <=1.10.12.0 - 1.10.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-3114 is an unspecified error with the P224() Curve implementation in Golang.
CVE-2021-3114 has a severity score of 6.5 (Medium).
The affected software includes Golang versions 1.11, 1.15, and Red Hat Go.
To fix CVE-2021-3114, update your Golang installation to the recommended versions or apply the provided patches.
The highest threat from CVE-2021-3114 is to confidentiality and integrity.