Due to improper index calculation, an incorrectly formatted language tag can cause Parse to panic via an out of bounds read. If Parse is used to process untrusted user inputs, this may be used as a vector for a denial of service attack.
golang-x-text in F34-Rawhide was updated to a patched version 5 months ago. I also just updated it in epel8. Please do not open bugs for this CVE against our packages.
This issue has been addressed in the following products: OpenShift Developer Tools and Services for OCP 4.7 Via RHSA-2022:5525 https://access.redhat.com/errata/RHSA-2022:5525
This issue has been addressed in the following products: Logging subsystem for Red Hat OpenShift 5.4 Via RHSA-2022:5556 https://access.redhat.com/errata/RHSA-2022:5556
Upstream commit for this issue: https://go.googlesource.com/text/+/383b2e75a7a4198c42f8f87833eefb772868a56f
This issue has been addressed in the following products: OpenShift Logging 5.3 Via RHSA-2022:5908 https://access.redhat.com/errata/RHSA-2022:5908
This issue has been addressed in the following products: OpenShift Logging 5.2 Via RHSA-2022:5909 https://access.redhat.com/errata/RHSA-2022:5909
*** Bug 2105594 has been marked as a duplicate of this bug. ***
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:5070 https://access.redhat.com/errata/RHSA-2022:5070
This issue has been addressed in the following products: RHOL-5.5-RHEL-8 Via RHSA-2022:6051 https://access.redhat.com/errata/RHSA-2022:6051
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 Via RHSA-2022:6346 https://access.redhat.com/errata/RHSA-2022:6346
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:6287 https://access.redhat.com/errata/RHSA-2022:6287
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.6 Via RHSA-2022:6263 https://access.redhat.com/errata/RHSA-2022:6263
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.9 Via RHSA-2022:6318 https://access.redhat.com/errata/RHSA-2022:6318
This issue has been addressed in the following products: RHEL-8-CNV-4.11 Via RHSA-2022:6526 https://access.redhat.com/errata/RHSA-2022:6526
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:6537 https://access.redhat.com/errata/RHSA-2022:6537
This issue has been addressed in the following products: RHEL-8-CNV-4.11 Via RHSA-2022:8750 https://access.redhat.com/errata/RHSA-2022:8750
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2022:7401 https://access.redhat.com/errata/RHSA-2022:7401
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2022:7399 https://access.redhat.com/errata/RHSA-2022:7399
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:0245 https://access.redhat.com/errata/RHSA-2023:0245
This issue has been addressed in the following products: RHEL-8-CNV-4.12 RHEL-7-CNV-4.12 Via RHSA-2023:0407 https://access.redhat.com/errata/RHSA-2023:0407
This issue has been addressed in the following products: RHEL-8-CNV-4.12 Via RHSA-2023:0408 https://access.redhat.com/errata/RHSA-2023:0408
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-38561
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:0566 https://access.redhat.com/errata/RHSA-2023:0566
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:0652 https://access.redhat.com/errata/RHSA-2023:0652
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:0774 https://access.redhat.com/errata/RHSA-2023:0774
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2023:0895 https://access.redhat.com/errata/RHSA-2023:0895
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2023:0890 https://access.redhat.com/errata/RHSA-2023:0890
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:1326 https://access.redhat.com/errata/RHSA-2023:1326
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:1328 https://access.redhat.com/errata/RHSA-2023:1328