Unrated severityNVD Advisory· Published Aug 8, 2021· Updated Aug 4, 2024
CVE-2021-36221
CVE-2021-36221
Description
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
Affected products
22- Go/Godescription
- osv-coords21 versionspkg:bitnami/golangpkg:rpm/almalinux/delvepkg:rpm/opensuse/go1.15&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.15&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/go1.15&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/go1.16&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.16&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/go1.16&distro=openSUSE%20Tumbleweedpkg:rpm/suse/go1.15&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3
< 1.15.15+ 20 more
- (no CPE)range: < 1.15.15
- (no CPE)range: < 1.6.0-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.15.15-lp152.26.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.2
- (no CPE)range: < 1.16.7-lp152.8.1
- (no CPE)range: < 1.16.7-1.23.1
- (no CPE)range: < 1.16.8-1.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.15.15-1.39.1
- (no CPE)range: < 1.16.7-1.23.1
- (no CPE)range: < 1.16.7-1.23.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MU47VKTNXX33ZDLTI2ORRUY3KLJKU6G/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HM7U5JNS5WU66Q3S26PFIU2ITB2ATTQ4/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4AMYYHGBYMIWCCR5RCDFI5RAUJOPO5L/mitrevendor-advisory
- security.gentoo.org/glsa/202208-02mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2022/01/msg00016.htmlmitremailing-list
- lists.debian.org/debian-lts-announce/2022/01/msg00017.htmlmitremailing-list
- lists.debian.org/debian-lts-announce/2023/04/msg00021.htmlmitremailing-list
- cert-portal.siemens.com/productcert/pdf/ssa-222547.pdfmitre
- groups.google.com/forum/mitre
- groups.google.com/g/golang-announce/c/JvWG9FUUYT0mitre
- groups.google.com/g/golang-announce/c/uHACNfXAZqkmitre
- www.oracle.com/security-alerts/cpujan2022.htmlmitre
News mentions
0No linked articles in our index yet.