CVE-2021-36221

Description

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.231

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Spectrum Protect Server 8.1.12Windows
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update aardvark-dns-1.1.0-4.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update buildah-1.27.0-2.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update buildah-debugsource-1.27.0-2.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update buildah-tests-1.27.0-2.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update cockpit-podman-53-1.module+el8.7.0+16772+33343656.noarch.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update conmon-2.1.4-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update conmon-debugsource-2.1.4-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update container-selinux-2.189.0-1.module+el8.7.0+16772+33343656.noarch.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update containernetworking-plugins-1.1.1-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update containernetworking-plugins-debugsource-1.1.1-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update containers-common-1-40.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update crit-3.15-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update criu-3.15-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update criu-debugsource-3.15-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update criu-devel-3.15-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update criu-libs-3.15-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update crun-1.5-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update crun-debugsource-1.5-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update fuse-overlayfs-1.9-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update fuse-overlayfs-debugsource-1.9-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update libslirp-4.4.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update libslirp-debugsource-4.4.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update libslirp-devel-4.4.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update netavark-1.1.0-6.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update oci-seccomp-bpf-hook-1.2.6-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update oci-seccomp-bpf-hook-debugsource-1.2.6-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update podman-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update podman-catatonit-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update podman-debugsource-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update podman-docker-4.2.0-1.module+el8.7.0+16772+33343656.noarch.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update podman-gvproxy-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update podman-plugins-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update podman-remote-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update podman-tests-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update python3-criu-3.15-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update python3-podman-4.2.0-1.module+el8.7.0+16772+33343656.noarch.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update runc-1.1.4-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update runc-debugsource-1.1.4-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update skopeo-1.9.2-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update skopeo-debugsource-1.9.2-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update skopeo-tests-1.9.2-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update slirp4netns-1.2.0-2.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update slirp4netns-debugsource-1.2.0-2.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update toolbox-0.0.99.3-0.6.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update toolbox-debugsource-0.0.99.3-0.6.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update toolbox-tests-0.0.99.3-0.6.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457) container-tools:rhel8 security, bug fix, and enhancement update udica-0.2.6-3.module+el8.7.0+16772+33343656.noarch.rpmLinux
SUSE-SU-2021:2787-1(SUSE Linux Enterprise Module for Development Tools 15-SP3 ) go1.15-1.15.15-1.39.1.x86_64.rpmLinux
SUSE-SU-2021:2787-1(SUSE Linux Enterprise Module for Development Tools 15-SP3 ) go1.15-doc-1.15.15-1.39.1.x86_64.rpmLinux
SUSE-SU-2021:2787-1(SUSE Linux Enterprise Module for Development Tools 15-SP3 ) go1.15-race-1.15.15-1.39.1.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update buildah-debuginfo-1.27.0-2.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update buildah-tests-debuginfo-1.27.0-2.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update conmon-debuginfo-2.1.4-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update containernetworking-plugins-debuginfo-1.1.1-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update criu-debuginfo-3.15-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update criu-libs-debuginfo-3.15-3.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update crun-debuginfo-1.5-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update fuse-overlayfs-debuginfo-1.9-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update libslirp-debuginfo-4.4.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update oci-seccomp-bpf-hook-debuginfo-1.2.6-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update podman-catatonit-debuginfo-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update podman-debuginfo-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update podman-gvproxy-debuginfo-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update podman-plugins-debuginfo-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update podman-remote-debuginfo-4.2.0-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update runc-debuginfo-1.1.4-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update skopeo-debuginfo-1.9.2-1.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update slirp4netns-debuginfo-1.2.0-2.module+el8.7.0+16772+33343656.x86_64.rpmLinux
(RHSA-2022:7457)Moderate: security, bug fix, and enhancement update toolbox-debuginfo-0.0.99.3-0.6.module+el8.7.0+16772+33343656.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234