vulnerability
Red Hat OpenShift: CVE-2021-3114: incorrect operations on the P-224 curve
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:N/AC:L/Au:N/C:P/I:P/A:N) | 2021-01-26 | 2021-03-31 | 2025-04-11 |
Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
2021-01-26
Added
2021-03-31
Modified
2025-04-11
Description
In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.
Solution(s)
linuxrpm-upgrade-cri-olinuxrpm-upgrade-cri-toolslinuxrpm-upgrade-golang-github-prometheus-promulinuxrpm-upgrade-ignitionlinuxrpm-upgrade-openshiftlinuxrpm-upgrade-openshift-clientslinuxrpm-upgrade-runc
References
- CVE-2021-3114
- https://attackerkb.com/topics/CVE-2021-3114
- REDHAT-RHSA-2021:0957
- REDHAT-RHSA-2021:0958
- REDHAT-RHSA-2021:1006
- REDHAT-RHSA-2021:1338
- REDHAT-RHSA-2021:1339
- REDHAT-RHSA-2021:1366
- REDHAT-RHSA-2021:1551
- REDHAT-RHSA-2021:1746
- REDHAT-RHSA-2021:2021
- REDHAT-RHSA-2021:2041
- REDHAT-RHSA-2021:2093
- REDHAT-RHSA-2021:2095
- REDHAT-RHSA-2021:2437
- REDHAT-RHSA-2021:2438
- REDHAT-RHSA-2021:3119
- REDHAT-RHSA-2021:4103
- REDHAT-RHSA-2021:4226
- REDHAT-RHSA-2022:0308

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.