RHSA-2021:2920MediumCVSS 8.6

Red Hat Security Advisory: OpenShift Virtualization 4.8.0 Images

Published
July 28, 2021
Last Modified
August 15, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2020-27813 — golang-github-gorilla-websocket: integer overflow leads to denial of service CVE-2020-29652 — golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference CVE-2021-3114 — golang: crypto/elliptic: incorrect operations on the P-224 curve CVE-2021-3121 — gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation CVE-2021-29482 — ulikunitz/xz: Infinite loop in readUvarint allows for denial of service

🎯 Affected products2

  • CNV 4.8 for RHEL 8
  • container-native-virtualization/vm-import-operator-rhel8@sha256:d5f101aa6d75dc70af48b74ab8e18b381f6956cb24fb79beaefecd0940233ae6_amd64 as a component of CNV 4.8 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (102)