CVE-2021-34558
MEDIUM6.5EPSS 0.92%Panic on certain certificates in crypto/tls
Published: 2/17/2022Modified: 4/28/2026
Also known as:DEBIAN-CVE-2021-34558
Description
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
Affected packages (3)
- Bitnami/golangfrom 0, < 1.15.14, >= 1.16.0, < 1.16.6
- Debian/golang-1.15from 0, < 1.15.9-6
- Go/stdlibfrom 0, < 1.15.14, >= 1.16.0-0, < 1.16.6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
References (21)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2021-34558
- PATCHhttps://go.dev/cl/334031
- PATCHhttps://go.googlesource.com/go/+/a98589711da5e9d935e8d690cfca92892e86d557
- REPORThttps://go.dev/issue/47143
- WEBhttps://golang.org/doc/devel/release#go1.16.minor
- WEBhttps://groups.google.com/g/golang-announce
- WEBhttps://groups.google.com/g/golang-announce/c/n9FxMelZGAQ
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BA7MFVXRBEKRTLSLYDICTYCGEMK2HZ7/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3XBQUFVI5TMV4KMKI7GKA223LHGPQISE/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6BTC3JQUASFN5U2XA4UZIGAPZQBD5JSS/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D7FRFM7WWR2JCT6NORQ7AO6B453OMI3I/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITRXPCHUCJGXCX2CUEPKZRRTB27GG4ZB/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYIUSR4YP52PWG7YE7AA3DZ5OSURNFJB/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LBMLUQMN6XRKPVOI5XFFBP4XSR7RNTYR/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLOGBB7XBBRB3J5FDPW5KWHSH7IRF64W/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXJ2MVMAHOIGRH37ZSFYC4EVWLJFL2EQ/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2021-34558
- WEBhttps://security.gentoo.org/glsa/202208-02
- WEBhttps://security.netapp.com/advisory/ntap-20210813-0005/
- WEBhttps://www.oracle.com/security-alerts/cpujan2022.html
- WEBhttps://www.oracle.com/security-alerts/cpuoct2021.html