Unrated severityNVD Advisory· Published Jan 26, 2021· Updated Aug 3, 2024
CVE-2021-3114
CVE-2021-3114
Description
In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.
Affected products
28- Go/Godescription
- osv-coords27 versionspkg:bitnami/golangpkg:rpm/almalinux/grafanapkg:rpm/opensuse/go1.14&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/go1.14&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.14&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/go1.15&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.15&distro=openSUSE%20Tumbleweedpkg:rpm/suse/go1.14&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/go1.14&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/go1.14&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/go1.14&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Server%204.0
< 1.14.14+ 26 more
- (no CPE)range: < 1.14.14
- (no CPE)range: < 7.5.9-4.el8
- (no CPE)range: < 1.14.14-lp151.28.1
- (no CPE)range: < 1.14.14-lp152.2.18.1
- (no CPE)range: < 1.14.15-1.6
- (no CPE)range: < 1.15.7-lp152.8.1
- (no CPE)range: < 1.15.15-1.2
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YWAYJGXWC232SG3UR3TR574E6BP3OSQQ/mitrevendor-advisoryx_refsource_FEDORA
- security.gentoo.org/glsa/202208-02mitrevendor-advisoryx_refsource_GENTOO
- www.debian.org/security/2021/dsa-4848mitrevendor-advisoryx_refsource_DEBIAN
- github.com/golang/go/commit/d95ca9138026cbe40e0857d76a81a16d03230871mitrex_refsource_CONFIRM
- groups.google.com/g/golang-announce/c/mperVMGa98wmitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2021/03/msg00014.htmlmitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2021/03/msg00015.htmlmitremailing-listx_refsource_MLIST
- security.netapp.com/advisory/ntap-20210219-0001/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.