Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-20291

23
FAUCET Score

CVE-2021-20291 is a deadlock vulnerability in github.com/containers/storage, affecting products like Fedora, Red Hat, and storage_project, where processing a malformed container image layer can cause an indefinite wait, leading to a Denial of Service (DoS). With a CVSS score of 6.5 (Medium), this vulnerability can be triggered remotely by an unauthenticated attacker, requiring user interaction to download and store a crafted malicious image. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered community discussion and media coverage, indicating awareness of its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.28.1CPE matchmatch criteria
cpe:2.3:a:storage_project:storage:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.59%
Probability of exploitation in next 30 days
EPSS Percentile
73.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0159 is in the 85th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

gopatch availablevia ghsa
Product: github.com/containers/storageFixed in: 1.28.1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:3.0-8050020220104131412.e34216c9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8-8050020210921082437.faa19cc5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: podman-2:4.2.0-3.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: skopeo-2:1.9.2-1.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: buildah-1:1.27.0-2.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: cri-o-0:1.20.2-6.rhaos4.7.gitf1d5201.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift-0:4.7.0-202104090228.p0.git.97111.77863f8.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.8Fixed in: openshift4/ose-docker-builder:v4.8.0-202107152024.p0.git.70b7b95.assembly.stream
View patch
redhatpatch availablevia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: osp-director-provisioner-container
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: rhosp-rhel8/osp-director-downloader
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: rhosp-rhel8/osp-director-operator

Vendor Advisories (2)

goGHSA-7qw8-847f-pggmmedium

Improper Locking in github.com/containers/storage

May 10, 2021
redhatCVE-2021-20291Moderate

containers/storage: DoS via malicious image

Apr 1, 2021

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/R5D7XL7FL24TWFMGQ3K2S72EOUSLZMKL
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SPYOHNG2Q7DCAQZMGYLMENLKALGDLG3X
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WX24EITRXVHDM5M223BVTJA2ODF2FSHI
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZNMB7O2UIXE34PGSCSOULGHPX5LIJBMM
unit42.paloaltonetworks.com / cve-2021-20291
ExploitThird Party Advisory