The fix for CVE-2021-33196 can be bypassed by crafted inputs. As a result, the NewReader and OpenReader functions in archive/zip can still cause a panic or an unrecoverable fatal error when reading an archive that claims to contain a large number of files, regardless of its actual size. References: https://groups.google.com/g/golang-announce/c/dx9d7IOseHw https://github.com/golang/go/issues/47801
Created golang tracking bugs for this issue: Affects: epel-all [bug 2006045] Affects: fedora-all [bug 2006047] Affects: openstack-rdo [bug 2006046]
Upstream patch: https://github.com/golang/go/commit/bacbc33439b124ffd7392c91a5f5d96eca8c0c0b [master] https://github.com/golang/go/commit/1dd24caf08985066b309af6bc461780c73e05c35 [1.17.1] https://github.com/golang/go/commit/6c480017ae600b2c90a264a922e041df04dfa785 [1.16.8]
This issue has been addressed in the following products: RHACS-3.67-RHEL-8 Via RHSA-2021:4902 https://access.redhat.com/errata/RHSA-2021:4902
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2022:0432 https://access.redhat.com/errata/RHSA-2022:0432
This issue has been addressed in the following products: Openshift Serveless 1.20 Via RHSA-2022:0434 https://access.redhat.com/errata/RHSA-2022:0434
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.9 Via RHSA-2022:0655 https://access.redhat.com/errata/RHSA-2022:0655
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:1819 https://access.redhat.com/errata/RHSA-2022:1819
This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.6 Via RHSA-2022:4814 https://access.redhat.com/errata/RHSA-2022:4814