Malformed binaries parsed using Open or OpenFat can cause a panic when calling ImportedSymbols, due to an out-of-bounds slice operation. Reference: https://github.com/golang/go/issues/48990
Created golang tracking bugs for this issue: Affects: epel-all [bug 2020726] Affects: fedora-all [bug 2020728] Affects: openstack-rdo [bug 2020727]
Upstream issue: https://github.com/golang/go/issues/48990
Upstream commits: 1.16: https://github.com/golang/go/commit/d19c5bdb24e093a2d5097b7623284eb02726cede 1.17: https://github.com/golang/go/commit/4a842985bf3f71d93a2b1340d9d6685bebc12b6b
This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.7 Via RHSA-2022:1734 https://access.redhat.com/errata/RHSA-2022:1734
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2022:1745 https://access.redhat.com/errata/RHSA-2022:1745
This issue has been addressed in the following products: Openshift Serveless 1.22 Via RHSA-2022:1747 https://access.redhat.com/errata/RHSA-2022:1747
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:1819 https://access.redhat.com/errata/RHSA-2022:1819
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-41771