CVE-2021-3121: Out-of-bounds Read
A flaw was found in github.com/gogo/protobuf before 1.3.2 that allows an out-of-bounds access when unmarshalling certain protobuf objects. This flaw allows a remote attacker to send crafted protobuf messages, causing panic and resulting in a denial of service. The highest threat from this vulnerability is to availability.
Other sources
An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kialito a version that resolves this vulnerability.Fixed in 0:v1.24.7.redhat1-1.el8 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.20.0-0.rhaos4.7.git8921e00.el8.51 - Upgrade
Upgrade
redhat/cri-toolsto a version that resolves this vulnerability.Fixed in 0:1.20.0-1.el8 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.7.0-202103251046.p0.git.3957.c4da68b.el7 - Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 0:4.8.0-202107161820.p0.git.051ac4f.assembly.stream.el8 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.8.0-202106281541.p0.git.1077b05.assembly.stream.el8 - Upgrade
Upgrade
redhat/github.com/gogo/protobufto a version that resolves this vulnerability.Fixed in 1.3.2
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:1679
- RHSA-2021:2136
- RHSA-2021:2374
- RHSA-2022:1276
- RHSA-2022:6916
- RHSA-2022:0056
- RHSA-2022:0577
- RHSA-2022:6536
- RHSA-2020:5634
- RHSA-2021:1006
- RHBA-2021:1365
- RHSA-2020:5633
- RHSA-2020:5635
- RHSA-2021:1005
- RHSA-2021:1007
- RHSA-2021:1225
- RHSA-2021:1227
- RHSA-2021:1552
- RHSA-2021:1563
- RHSA-2021:2121
- RHSA-2021:2286
- RHSA-2021:2977
- RHSA-2021:3262
- RHSA-2021:3303
- RHSA-2022:0283
- RHSA-2021:2437
- RHSA-2021:2438
- RHBA-2021:3760
- RHSA-2021:3759
- RHSA-2021:0799
- RHSA-2021:4104
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-3121.
What is the severity of CVE-2021-3121?
The severity of CVE-2021-3121 is high with a CVSS score of 8.6.
What is the affected software?
The affected software includes github.com/gogo/protobuf versions up to 1.3.2, kiali up to v1.24.7.redhat1-1.el8, cri-o up to 1.20.0-0.rhaos4.7.git8921e00.el8.51, cri-tools up to 1.20.0-1.el8, and others.
How does this vulnerability occur?
This vulnerability occurs due to an out-of-bounds access when unmarshalling certain protobuf objects in github.com/gogo/protobuf.
How can I fix CVE-2021-3121?
To fix CVE-2021-3121, update your golang/protobuf package to version 1.3.2 or newer and apply any available patches or updates for the affected software.