Improper Certificate Validation in Go programming language - CVE-2021-34558
Published: August 9, 2021 / Updated: August 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper certificate verification in crypto/tls package in Go when processing X.509 certificates. The application does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
Affected software
Gentoo Linux
Arch Linux
Oracle Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Module for Development Tools
openEuler
golang-github-prometheus-promu (Red Hat package)
containernetworking-plugins (Red Hat package)
golang-github-vbatts-tar-split (Red Hat package)
butane (Red Hat package)
kubevirt (Red Hat package)
go-toolset-1.15 (Red Hat package)
go-toolset-1.15-golang (Red Hat package)
cri-o (Red Hat package)
cri-tools (Red Hat package)
ignition (Red Hat package)
jenkins (Red Hat package)
etcd (Red Hat package)
openshift-kuryr (Red Hat package)
openshift-ansible (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
openstack-ironic (Red Hat package)
ovn2.13 (Red Hat package)
redhat-release-coreos (Red Hat package)
toolbox-tests
toolbox
udica
containernetworking-plugins
rosa (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
delve
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
golang
golang-help
golang-devel
golang-misc
go-toolset
golang-bin
golang-race
golang-tests
golang-docs
golang-src
go1.15-race
go1.15-doc
go1.15
buildah
buildah-debugsource
buildah-debuginfo
buildah-tests
containers-common
go
conmon
container-selinux
podman
python3-criu
criu-libs
criu-devel
criu
crit
podman (Red Hat package)
libslirp-devel
libslirp
python3-podman
podman-gvproxy
podman-catatonit
podman-plugins
podman-remote
podman-tests
podman-docker
mcg (Red Hat package)
grafana (Red Hat package)
grafana
cockpit-podman
ObjectScale
Asset Repository in IBM Cloud Pak for Integration (CP4I)
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Dell PowerProtect Cyber Recovery
Red Hat Developer Tools
App Connect Enterprise Certified Container
IBM Cloud Pak for Multicloud Management Monitoring
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Automation Manager
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Operations Dashboard
Red Hat Advanced Cluster Management for Kubernetes
QRadar Suite
Juniper Secure Analytics (JSA)
Splunk Enterprise
Red Hat OpenShift Jaeger
IBM Cloud Pak System
Red Hat Container Native Virtualization
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
IBM Qradar SIEM
Cloud Pak for Data
IBM Security Verify Access
How to mitigate CVE-2021-34558
golang-github-prometheus-promu (Red Hat package) - update to 0.5.0-4.git642a960.el8
containernetworking-plugins (Red Hat package) - update to 0.8.6-3.rhaos4.6.el7
golang-github-vbatts-tar-split (Red Hat package) - update to 0.11.1-6.el8ost
butane (Red Hat package) - update to 0.12.1-2.rhaos4.8.el8
kubevirt (Red Hat package) - addressed in versions 2.6.8-211.el7, 2.6.8-211.el8, 4.8.5-278.el7, 4.8.5-278.el8
ObjectScale - update to 1.3.0
App Connect Enterprise Certified Container - addressed in versions 1.1.3, 1.5.2
QRadar Suite - update to 1.10.18.0
go-toolset-1.15 (Red Hat package) - update to 1.15.14-1.el7_9
go-toolset-1.15-golang (Red Hat package) - update to 1.15.14-1.el7_9
Red Hat OpenShift Jaeger - update to 1.20.5
cri-o (Red Hat package) - addressed in versions 1.19.3-8.rhaos4.6.git0fa2911.el7, 1.19.3-8.rhaos4.6.git0fa2911.el8, 1.20.4-7.rhaos4.7.git6287500.el7, 1.20.4-7.rhaos4.7.git6287500.el8, 1.21.2-8.rhaos4.8.git8d4264e.el7, 1.21.2-8.rhaos4.8.git8d4264e.el8, 1.21.2-13.rhaos4.8.git52b3f98.el7, 1.21.2-13.rhaos4.8.git52b3f98.el8, 1.21.3-6.rhaos4.8.gite34bf50.el7, 1.21.3-6.rhaos4.8.gite34bf50.el8
cri-tools (Red Hat package) - update to 1.21.0-3.el8
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 2.2.1-patch-4, 4.0.2
OpenShift Virtualization - addressed in versions 2.6.7, 2.6.8, 4.8.1, 4.8.2, 4.8.5, 4.9.0, 4.9.2, 4.10.0
ignition (Red Hat package) - addressed in versions 2.6.0-8.rhaos4.6.git947598e.el8, 2.9.0-4.rhaos4.7.git1d56dc8.el8, 2.9.0-7.rhaos4.8.el8
jenkins (Red Hat package) - update to 2.289.3.1633554819-1.el8
etcd (Red Hat package) - update to 3.3.23-7.el8ost
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 4
Red Hat OpenShift Container Platform - addressed in versions 4.6.42, 4.7.23, 4.8.4, 4.8.9, 4.8.15
openshift-kuryr (Red Hat package) - addressed in versions 4.6.0-202107300032.p0.git.0063daa.el8, 4.7.0-202107291238.p0.git.c7654fb.assembly.stream.el8, 4.8.0-202107291413.p0.git.8a4c2d8.assembly.stream.el8
openshift-ansible (Red Hat package) - addressed in versions 4.6.0-202107292126.p0.git.4ec6967.el7, 4.7.0-202107292046.p0.git.e1b19c2.assembly.stream.el7, 4.8.0-202107292023.p0.git.626f7a3.assembly.stream.el7, 4.8.0-202109241839.p0.git.4bb45f8.assembly.stream.el7
openshift (Red Hat package) - addressed in versions 4.6.0-202107292126.p0.git.4c3480d.el7, 4.6.0-202107292126.p0.git.4c3480d.el8, 4.7.0-202107292242.p0.git.558d959.assembly.stream.el7, 4.7.0-202107292242.p0.git.558d959.assembly.stream.el8, 4.8.0-202107300027.p0.git.38b3ecc.assembly.stream.el7, 4.8.0-202107300027.p0.git.38b3ecc.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.6.0-202107292126.p0.git.2b525e8.el7, 4.6.0-202107292126.p0.git.2b525e8.el8, 4.7.0-202107292242.p0.git.8b4b094.assembly.stream.el7, 4.7.0-202107292242.p0.git.8b4b094.assembly.stream.el8, 4.8.0-202107292313.p0.git.1077b05.assembly.stream.el7, 4.8.0-202107292313.p0.git.1077b05.assembly.stream.el8, 4.8.0-202108120034.p0.git.0d10c3f.assembly.stream.el7, 4.8.0-202108120034.p0.git.0d10c3f.assembly.stream.el8
atomic-openshift-service-idler (Red Hat package) - addressed in versions 4.6.0-202107291238.p0.git.39cfc66.el8, 4.7.0-202107291238.p0.git.39cfc66.assembly.stream.el8, 4.8.0-202107291413.p0.git.39cfc66.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.8.1633555500-1.el8
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Red Hat OpenStack - update to 16.2
openstack-ironic (Red Hat package) - update to 17.0.4-0.20210730151213.5b801be.el8
ovn2.13 (Red Hat package) - update to 20.12.0-140.el8fdp
redhat-release-coreos (Red Hat package) - update to 47.84-1.el8
Asset Repository in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-3, 2021.2.1-1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-4, 2021.3.1
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
containernetworking-plugins - addressed in versions 1.0.0-0.3.rc1.fc33, 1.0.0-0.3.rc1.fc34
rosa (Red Hat package) - update to 1.1.1-51c4a5e.el8
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-2.0.1
delve - update to 1.5.0-2
Migration Toolkit for Containers - update to 1.5.1
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
golang - update to 1.15.7-5
golang-help - update to 1.15.7-5
golang-devel - update to 1.15.7-5
golang-misc - update to 1.15.14-1
go-toolset - update to 1.15.14-1
golang - update to 1.15.14-1
golang-bin - update to 1.15.14-1
golang-race - update to 1.15.14-1
golang-tests - update to 1.15.14-1
golang-docs - update to 1.15.14-1
golang-src - update to 1.15.14-1
golang - addressed in versions 1.15.14-1.el7, 1.15.14-1.fc33, 1.16.6-1.fc34
go1.15-race - update to 1.15.14-1.36.1
go1.15-doc - update to 1.15.14-1.36.1
go1.15 - update to 1.15.14-1.36.1
buildah - addressed in versions 1.21.4-5.fc33, 1.21.4-5.fc34
buildah-debugsource - update to 1.26.1-4
buildah - update to 1.26.1-4
buildah-debuginfo - update to 1.26.1-4
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common - update to 1-81.0.1
go - update to 2
conmon - update to 2.1.10-1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.2
container-selinux - update to 2.229.0-2
podman - addressed in versions 3.2.3-2.fc33, 3.2.3-2.fc34
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
podman (Red Hat package) - update to 4.2.0-3.el9
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.9.0, 4.10.0
python3-podman - update to 4.9.0-1
podman-gvproxy - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
mcg (Red Hat package) - update to 5.9.0-28.61dcf87.5.9.el8
grafana (Red Hat package) - update to 7.5.9-4.el8
grafana - addressed in versions 7.5.9-4.fc34, 7.5.10-1.fc34
IBM Security Verify Access - update to 10.0.9
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
cockpit-podman - update to 84.1-1
Links to Public Exploits and PoC-codes
External References
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce/c/n9FxMelZGAQ
- https://golang.org/doc/devel/release#go1.16.minor
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BA7MFVXRBEKRTLSLYDICTYCGEMK2HZ7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D7FRFM7WWR2JCT6NORQ7AO6B453OMI3I/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXJ2MVMAHOIGRH37ZSFYC4EVWLJFL2EQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JYIUSR4YP52PWG7YE7AA3DZ5OSURNFJB/
Related Security Bulletins
- Denial of service in Go programming language
- Red Hat Developer Tools update for go-toolset-1.15 and go-toolset-1.15-golang
- Red Hat Enterprise Linux 8.4 update for the go-toolset:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in OpenShift Container Platform 4.7
- Multiple vulnerabilities in OpenShift Container Platform 4.8
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in IBM Watson Discovery for IBM Cloud Pak for Data
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in OpenShift Container Platform 4.8
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Red Hat OpenShift Virtualization update for kubevirt
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Improper Certificate Validation in IBM Cloud Pak for Multicloud Management Security Services
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Red Hat OpenStack Platform 16 update for etcd
- Denial of service in Red Hat OpenShift Service on AWS (ROSA)
- Red Hat OpenStack Platform 16 update for etcd
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Red Hat OpenStack Platform 16.1 update for golang-github-vbatts-tar-split
- Red Hat OpenStack Platform 16.2 update for golang-github-vbatts-tar-split
- Multiple vulnerabilities in Red Hat OpenShift Virtualization 4.8
- SUSE update for go1.15
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Gentoo update for Go
- Multiple vulnerabilities in IBM Cloud Pak for Integration
- Multiple vulnerabilities in IBM Operations Dashboard
- Denial of service in IBM Cloud Automation Manager
- Denial of service in IBM App Connect Enterprise Certified Container
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 8 update for grafana
- Arch Linux update for go
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM QRadar Suite Software
- openEuler update for golang
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Improper certificate validation in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.6
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.9
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.9
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.10
- Fedora 34 update for golang
- Fedora 33 update for golang
- Fedora 34 update for containernetworking-plugins
- Fedora 33 update for containernetworking-plugins
- Fedora 34 update for buildah
- Fedora 33 update for buildah
- Fedora 34 update for podman
- Fedora 33 update for podman
- Fedora EPEL 7 update for golang
- Fedora 34 update for grafana
- Fedora 34 update for grafana
- openEuler 22.03 LTS SP4 update for buildah
- Multiple vulnerabilities in IBM Security Verify Access
- Anolis OS update for go-toolset:an8 module
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Cloud Pak System