Hide Forgot
The go command may execute arbitrary code at build time when users have “.” listed explicitly in their PATH and are running “go get” or build commands outside of a module or with module mode disabled.
Created golang tracking bugs for this issue: Affects: epel-all [bug 1918762] Affects: fedora-all [bug 1918763]
https://go-review.googlesource.com/c/go/+/284783/ Upstream patch
Upstream issue and commit: https://github.com/golang/go/issues/43783 https://github.com/golang/go/commit/46e2e2e9d99925bbf724b12693c6d3e27a95d6a0
External References: https://groups.google.com/g/golang-announce/c/mperVMGa98w
Statement: While OpenShift Container Platform (OCP), Red Hat OpenShift Jaeger (RHOSJ), OpenShift Service Mesh (OSSM) and OpenShift Virtualization all contain RPMs and containers which are compiled with a vulnerable version of Go, the vulnerability is specific to the building of Go code itself. Hence the relevant components have been marked as not affected. Additionally, only the main RPMs and containers for OCP, RHOSJ, OSSM and OpenShift Virtualization are represented due to the large volume of not affected components.
Mitigation: The flaw can be mitigated by making sure "." is not in your PATH environment variable.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-3115
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2021:1339 https://access.redhat.com/errata/RHSA-2021:1339
This issue has been addressed in the following products: Openshift Serveless 1.14 Via RHSA-2021:1338 https://access.redhat.com/errata/RHSA-2021:1338
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1746 https://access.redhat.com/errata/RHSA-2021:1746
This issue has been addressed in the following products: Openshift Serveless 1.10 Via RHSA-2021:2021 https://access.redhat.com/errata/RHSA-2021:2021
This issue has been addressed in the following products: Openshift Serveless 1.14 Via RHSA-2021:2093 https://access.redhat.com/errata/RHSA-2021:2093
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2021:2095 https://access.redhat.com/errata/RHSA-2021:2095