The vendor explicitly identifies these products as affected by this CVE.
- servicemesh-cni as a component of OpenShift Service Mesh 2.0
- servicemesh-cni.src as a component of OpenShift Service Mesh 2.0
- go.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- golang-bin as a component of Red Hat Ceph Storage 2
- golang-src as a component of Red Hat Ceph Storage 2
- golang.src as a component of Red Hat Ceph Storage 2
- golang-bin as a component of Red Hat Ceph Storage 3
- golang-src as a component of Red Hat Ceph Storage 3
- golang.src as a component of Red Hat Ceph Storage 3
- buildah.src as a component of Red Hat Enterprise Linux 7
- golang as a component of Red Hat Enterprise Linux 7
- golang-bin as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in golang.org. In x/text, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag.
- Remediation
- The OpenShift Service Mesh release notes provide information on the features and known issues: https://docs.openshift.com/container-platform/latest/service_mesh/v2x/servicemesh-release-notes.html
