CVE-2021-3114
Description
RHSA-2021:4226: grafana security, bug fix, and enhancement update (Moderate)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description golang: crypto/elliptic: incorrect operations on the P-224 curve Red Hat statement OpenShift ServiceMesh (OSSM) 1.1 is Out Of Support Scope (OOSS) for Moderate and Low impact vulnerabilities because it is now in the Maintenance Phase of the support. CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Native Client for RHELβ¦
Description
golang: crypto/elliptic: incorrect operations on the P-224 curve
Red Hat statement
OpenShift ServiceMesh (OSSM) 1.1 is Out Of Support Scope (OOSS) for Moderate and Low impact vulnerabilities because it is now in the Maintenance Phase of the support.
CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Native Client for RHEL 7 for Red Hat Storage | heketi-0:10.4.0-2.el7rhgs | RHSA-2022:0308 | 2022-01-27T00:00:00Z |
| OpenShift Logging 5.0 | openshift-logging/cluster-logging-rhel8-operator:v5.0.2-6 | RHBA-2021:1167 | 2021-04-12T00:00:00Z |
| OpenShift Logging 5.0 | openshift-logging/elasticsearch-proxy-rhel8:v5.0.2-5 | RHBA-2021:1167 | 2021-04-12T00:00:00Z |
| OpenShift Logging 5.0 | openshift-logging/elasticsearch-rhel8-operator:v5.0.2-5 | RHBA-2021:1167 | 2021-04-12T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/client-kn-rhel8:0.16.1-4 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/ingress-rhel8-operator:1.10.2-1 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/knative-rhel8-operator:1.10.2-1 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/kn-cli-artifacts-rhel8:0.16.1-4 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/kourier-control-rhel8:0.16.0-7 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serverless-operator-bundle:1.10.2-4 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serverless-rhel8-operator:1.10.2-1 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serving-activator-rhel8:0.16.0-6 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serving-autoscaler-hpa-rhel8:0.16.0-6 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serving-autoscaler-rhel8:0.16.0-6 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serving-controller-rhel8:0.16.0-6 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serving-queue-rhel8:0.16.0-6 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serving-storage-version-migration-rhel8:0.16.0-6 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/serving-webhook-rhel8:0.16.0-6 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.10 | openshift-serverless-1/svls-must-gather-rhel8:1.10.2-1 | RHSA-2021:2021 | 2021-05-19T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/client-kn-rhel8:0.20.0-9 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-controller-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-mtbroker-filter-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-mtbroker-ingress-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-mtchannel-broker-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-mtping-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-storage-version-migration-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-sugar-controller-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/eventing-webhook-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/ingress-rhel8-operator:1.14.0-9 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/knative-rhel8-operator:1.14.0-9 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/kn-cli-artifacts-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/kourier-control-rhel8:0.20.0-6 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serverless-operator-bundle:1.14.0-9 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serverless-rhel8-operator:1.14.0-9 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-activator-rhel8:0.20.0-9 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-autoscaler-hpa-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-autoscaler-rhel8:0.20.0-9 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-controller-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-domain-mapping-rhel8:0.20.0-9 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-domain-mapping-webhook-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-queue-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-storage-version-migration-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serving-webhook-rhel8:0.20.0-8 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/svls-must-gather-rhel8:1.14.0-12 | RHSA-2021:1338 | 2021-04-22T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/knative-rhel8-operator:1.14.1-2 | RHSA-2021:2093 | 2021-05-24T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/kn-cli-artifacts-rhel8:0.20.0-11 | RHSA-2021:2093 | 2021-05-24T00:00:00Z |
| Openshift Serveless 1.14 | openshift-serverless-1/serverless-operator-bundle:1.14.1-3 | RHSA-2021:2093 | 2021-05-24T00:00:00Z |
| Openshift Serverless 1 on RHEL 8 | openshift-serverless-clients-0:0.20.0-6.el8 | RHSA-2021:1339 | 2021-04-22T00:00:00Z |
| Openshift Serverless 1 on RHEL 8 | openshift-serverless-clients-0:0.20.0-7.el8 | RHSA-2021:2095 | 2021-05-24T00:00:00Z |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8-8040020210122160957.9f461222 | RHSA-2021:1746 | 2021-05-18T00:00:00Z |
| Red Hat Enterprise Linux 8 | grafana-0:7.5.9-4.el8 | RHSA-2021:4226 | 2021-11-09T00:00:00Z |
| Red Hat Gluster Storage 3.5 for RHEL 7 | rhgs3/rhgs-gluster-block-prov-rhel7:3.11.8-1 | RHSA-2021:3748 | 2021-10-07T00:00:00Z |
| Red Hat Gluster Storage 3.5 for RHEL 7 | heketi-0:10.4.0-2.el7rhgs | RHSA-2022:0308 | 2022-01-27T00:00:00Z |
| Red Hat OpenShift Container Platform 4.6 | ignition-0:2.6.0-7.rhaos4.6.git947598e.el8 | RHBA-2021:1522 | 2021-05-20T00:00:00Z |
| Red Hat OpenShift Container Platform 4.7 | openshift-0:4.7.0-202103181538.p0.git.97109.7576cdc.el7 | RHSA-2021:0958 | 2021-03-30T00:00:00Z |
| Red Hat OpenShift Container Platform 4.7 | openshift-clients-0:4.7.0-202103191426.p0.git.3953.f3a7513.el7 | RHSA-2021:0958 | 2021-03-30T00:00:00Z |
| Red Hat OpenShift Container Platform 4.7 | cri-o-0:1.20.2-4.rhaos4.7.gitd5a999a.el7 | RHSA-2021:1006 | 2021-04-05T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| OpenShift Serverless | knative-eventing | Affected |
| OpenShift Service Mesh 1 | ior | Out of support scope |
| OpenShift Service Mesh 1 | kiali | Out of support scope |
| OpenShift Service Mesh 1 | servicemesh | Out of support scope |
| OpenShift Service Mesh 1 | servicemesh-cni | Out of support scope |
| OpenShift Service Mesh 1 | servicemesh-grafana | Out of support scope |
| OpenShift Service Mesh 1 | servicemesh-operator | Out of support scope |
| OpenShift Service Mesh 1 | servicemesh-prometheus | Out of support scope |
| OpenShift Service Mesh 1 | servicemesh-proxy | Out of support scope |
| OpenShift Service Mesh 2.0 | 3scale-istio-adapter-rhel8-container | Affected |
| OpenShift Service Mesh 2.0 | kiali | Affected |
| OpenShift Service Mesh 2.0 | servicemesh | Affected |
| OpenShift Service Mesh 2.0 | servicemesh-cni | Affected |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected |
| OpenShift Service Mesh 2.0 | servicemesh-operator | Affected |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected |
| OpenShift Service Mesh 2.0 | servicemesh-proxy | Affected |
| Red Hat Ceph Storage 2 | golang | Out of support scope |
| Red Hat Ceph Storage 2 | grafana | Out of support scope |
| Red Hat Ceph Storage 3 | golang | Out of support scope |
| Red Hat Ceph Storage 3 | golang-github-prometheus-node_exporter | Out of support scope |
| Red Hat Ceph Storage 3 | grafana | Affected |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Will not fix |
| Red Hat Enterprise Linux 7 | buildah | Out of support scope |
| Red Hat Enterprise Linux 7 | compat-sap-c++-7 | Out of support scope |
| Red Hat Enterprise Linux 7 | compat-sap-c++-8 | Out of support scope |
| Red Hat Enterprise Linux 7 | compat-sap-c++-9 | Out of support scope |
| Red Hat Enterprise Linux 7 | docker | Out of support scope |
| Red Hat Enterprise Linux 7 | docker-distribution | Out of support scope |
| Red Hat Enterprise Linux 7 | etcd | Out of support scope |
| Red Hat Enterprise Linux 7 | etcd3 | Out of support scope |
| Red Hat Enterprise Linux 7 | flannel | Out of support scope |
| Red Hat Enterprise Linux 7 | gcc | Not affected |
| Red Hat Enterprise Linux 7 | gcc-libraries | Out of support scope |
| Red Hat Enterprise Linux 7 | golang | Out of support scope |
| Red Hat Enterprise Linux 7 | podman | Out of support scope |
| Red Hat Enterprise Linux 7 | scap-security-guide | Out of support scope |
| Red Hat Enterprise Linux 7 | skopeo | Out of support scope |
| Red Hat Enterprise Linux 8 | compat-sap-c++-9 | Not affected |
| Red Hat Enterprise Linux 8 | container-tools:1.0/buildah | Will not fix |
| Red Hat Enterprise Linux 8 | container-tools:1.0/podman | Out of support scope |
| Red Hat Enterprise Linux 8 | container-tools:1.0/skopeo | Out of support scope |
| Red Hat Enterprise Linux 8 | container-tools:2.0/buildah | Will not fix |
| Red Hat Enterprise Linux 8 | container-tools:2.0/podman | Affected |
| Red Hat Enterprise Linux 8 | container-tools:2.0/skopeo | Affected |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/buildah | Will not fix |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/podman | Affected |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/skopeo | Affected |
| Red Hat Enterprise Linux 8 | gcc | Not affected |
| Red Hat Enterprise Linux 8 | gcc-toolset-10-gcc | Not affected |
| Red Hat Enterprise Linux 8 | gcc-toolset-9-gcc | Not affected |
| Red Hat Enterprise Linux 9 | go-toolset | Not affected |
| Red Hat Enterprise Linux 9 | grafana | Not affected |
| Red Hat OpenShift Container Platform 3.11 | ansible-service-broker | Will not fix |
| Red Hat OpenShift Container Platform 3.11 | apb | Will not fix |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Will not fix |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler | Will not fix |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler | Will not fix |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry | Will not fix |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-metrics-server | Will not fix |
Apply commands
yum update -y heketi
# or:
dnf upgrade -y heketi
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | OpenShift Serverless | Affected |
| redhat | OpenShift Service Mesh 2.0 | Affected |
| redhat | OpenShift Service Mesh 2.0 | Affected |
| redhat | OpenShift Service Mesh 2.0 | Affected |
| redhat | OpenShift Service Mesh 2.0 | Affected |
| redhat | OpenShift Service Mesh 2.0 | Affected |
| redhat | OpenShift Service Mesh 2.0 | Affected |
| redhat | OpenShift Service Mesh 2.0 | Affected |
| redhat | OpenShift Service Mesh 2.0 | Affected |
| redhat | Red Hat Ceph Storage 3 | Affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat OpenShift Container Platform 4 | Affected |
| redhat | Red Hat OpenShift Container Platform 4 | Affected |
| redhat | Red Hat OpenShift Container Platform 4 | Affected |
| redhat | Red Hat OpenShift Container Platform 4 | Affected |
| redhat | Red Hat OpenShift Container Platform 4 | Not affected |
| redhat | Red Hat OpenShift Container Platform 4 | Affected |
| redhat | Red Hat OpenShift Container Platform Assisted Installer 1 | Affected |
| redhat | Red Hat Openshift Container Storage 4 | Affected |
| redhat | Red Hat Openshift Container Storage 4 | Affected |
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Affected | β |
Arch Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Fixed | 2:1.15.7-1 |
Debian Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| bullseye | Fixed | 1.15.7-1 |
Red Hat Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | stdlib | >=1.15.0-0,<1.15.7 | 1.14.14 |
References
- https://security.archlinux.org/ASA-202101-27
- https://www.suse.com/security/cve/CVE-2021-3114.html
- https://go.dev/cl/284779
- https://go.googlesource.com/go/+/d95ca9138026cbe40e0857d76a81a16d03230871
- https://go.dev/issue/43786
- https://groups.google.com/g/golang-announce/c/mperVMGa98w
- https://security-tracker.debian.org/tracker/CVE-2021-3114
- https://errata.rockylinux.org/RLSA-2021:4226
- https://errata.rockylinux.org/RLSA-2021:1746
- https://errata.almalinux.org/8/ALSA-2021-4226.html
- https://access.redhat.com/errata/RHSA-2021:1746
- https://access.redhat.com/errata/RHSA-2021:4226
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.