CVE-2021-36221
golang: net/http/httputil: panic due to racy read of persistConn after handler panic
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
Go versiones anteriores a 1.15.15 y 1.16.x versiones anteriores a 1.16.7, presenta una condición de carrera que puede conllevar un pánico de net/http/httputil ReverseProxy al abortar ErrAbortHandler
A race condition flaw was found in Go. The incoming requests body weren't closed after the handler panic and as a consequence this could lead to ReverseProxy crash. The highest threat from this vulnerability is to Availability.
OpenShift sandboxed containers support for OpenShift Container Platform provides users with built-in support for running Kata containers as an additional, optional runtime. This advisory contains an update for OpenShift sandboxed containers with enhancements, security updates, and bug fixes. Space precludes documenting all of the updates to OpenShift sandboxed containers in this advisory.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-07 CVE Reserved
- 2021-08-08 CVE Published
- 2024-08-04 CVE Updated
- 2025-05-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
https://groups.google.com/forum/#%21forum/golang-announce | ||
https://groups.google.com/g/golang-announce/c/JvWG9FUUYT0 | Mailing List | |
https://groups.google.com/g/golang-announce/c/uHACNfXAZqk | Mailing List | |
https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html | Mailing List |
|
https://www.oracle.com/security-alerts/cpujan2022.html | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Scalance Lpe9403 Firmware Search vendor "Siemens" for product "Scalance Lpe9403 Firmware" | < 2.0 Search vendor "Siemens" for product "Scalance Lpe9403 Firmware" and version " < 2.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance Lpe9403 Search vendor "Siemens" for product "Scalance Lpe9403" | - | - |
Safe
|
Golang Search vendor "Golang" | Go Search vendor "Golang" for product "Go" | < 1.15.15 Search vendor "Golang" for product "Go" and version " < 1.15.15" | - |
Affected
| ||||||
Golang Search vendor "Golang" | Go Search vendor "Golang" for product "Go" | >= 1.16.0 < 1.16.7 Search vendor "Golang" for product "Go" and version " >= 1.16.0 < 1.16.7" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 35 Search vendor "Fedoraproject" for product "Fedora" and version "35" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Timesten In-memory Database Search vendor "Oracle" for product "Timesten In-memory Database" | < 21.1.1.1.0 Search vendor "Oracle" for product "Timesten In-memory Database" and version " < 21.1.1.1.0" | - |
Affected
|