vulnerability
Red Hat OpenShift: CVE-2021-36221: golang: net/http/httputil: panic due to racy read of persistConn after handler panic
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:M/Au:N/C:N/I:N/A:P) | Aug 8, 2021 | Feb 24, 2022 | Apr 11, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Aug 8, 2021
Added
Feb 24, 2022
Modified
Apr 11, 2025
Description
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
Solution(s)
linuxrpm-upgrade-cri-olinuxrpm-upgrade-cri-toolslinuxrpm-upgrade-ignitionlinuxrpm-upgrade-openshiftlinuxrpm-upgrade-openshift-clientslinuxrpm-upgrade-openshift4-wincw-windows-machine-config-rhel8-operator
References
- CVE-2021-36221
- https://attackerkb.com/topics/CVE-2021-36221
- REDHAT-RHSA-2021:4156
- REDHAT-RHSA-2021:4765
- REDHAT-RHSA-2021:4766
- REDHAT-RHSA-2022:0557
- REDHAT-RHSA-2022:0561
- REDHAT-RHSA-2022:0577
- REDHAT-RHSA-2022:0855
- REDHAT-RHSA-2022:0947
- REDHAT-RHSA-2022:1276
- REDHAT-RHSA-2022:1361
- REDHAT-RHSA-2022:1372
- REDHAT-RHSA-2022:1396
- REDHAT-RHSA-2022:4668
- REDHAT-RHSA-2022:7457

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.