VDB

RHBA-2020%3A0492

RHBA-2020%3A0492 PUBLISHED CVSS 3.5 LOW

A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process responsible for pulling the image.

Risk Scores

CVSS 3.1
3.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-tests@sha256:aea74160222e2a84ae7e4e810ef0434900ce8a3598fa9f7266a49b073d090655_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-tests@sha256:aea74160222e2a84ae7e4e810ef0434900ce8a3598fa9f7266a49b073d090655_amd64
Red Hatopenshift4/ose-docker-builder@sha256:292225c7c7fa7e861b4dac81d5e84dd98017d986d0343b6e11a30b6bef2d986d_amd64 as a component of Red Hat OpenShift Container Platform 4.3*
Red Hatopenshift4/ose-keepalived-ipfailover@sha256:088cdc1351cdf238a18cb922fa1db1e7e2216db759c0339c9d87d1a6073635bf_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-keepalived-ipfailover@sha256:088cdc1351cdf238a18cb922fa1db1e7e2216db759c0339c9d87d1a6073635bf_amd64
Red Hatopenshift4/ose-logging-eventrouter@sha256:5eaa880a74d2288d47ad9ca940b5b0f54b86ac6bcf2cd59c267e0cd20768edef_amd64 as a component of Red Hat OpenShift Container Platform 4.3*
Red Hatopenshift4/ose-jenkins-agent-maven@sha256:1d5f3ab5a2a8c6b31f558882cdba0029fc6f9d03e6467459bda6a7bcac683a5e_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-jenkins-agent-maven@sha256:1d5f3ab5a2a8c6b31f558882cdba0029fc6f9d03e6467459bda6a7bcac683a5e_amd64
Red Hatopenshift4/ose-multus-cni@sha256:c31100d691fb02be7b9a97059aef33205728a2194112e18dfb59344178014109_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-multus-cni@sha256:c31100d691fb02be7b9a97059aef33205728a2194112e18dfb59344178014109_amd64
Red Hatopenshift4/ose-csi-external-provisioner-rhel7@sha256:27e35fdeb40b374a8b1a43ed4fecf6cd0285aba503f30ebe6198ae9a60e61841_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-csi-external-provisioner-rhel7@sha256:27e35fdeb40b374a8b1a43ed4fecf6cd0285aba503f30ebe6198ae9a60e61841_amd64
Red Hatopenshift4/ose-metering-ansible-operator@sha256:819d389930bb7d239740e1dac73f8daeeb3eae74edaeaf4680b3716481a9ba75_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-metering-ansible-operator@sha256:819d389930bb7d239740e1dac73f8daeeb3eae74edaeaf4680b3716481a9ba75_amd64
Red Hatopenshift4/ose-cluster-monitoring-operator@sha256:67896bff13cc964dbd3a2838948a8f5f6060d932ff433d248ff7f66b3f7d62d8_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-cluster-monitoring-operator@sha256:67896bff13cc964dbd3a2838948a8f5f6060d932ff433d248ff7f66b3f7d62d8_amd64
Red Hatopenshift4/ose-cluster-autoscaler-operator@sha256:98c883ba55ead6570cb4478ab87ba363577d347f9281a992cde92964463eab94_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-cluster-autoscaler-operator@sha256:98c883ba55ead6570cb4478ab87ba363577d347f9281a992cde92964463eab94_amd64
Red Hatopenshift4/ose-ironic-hardware-inventory-recorder-rhel8@sha256:7a7503a9ed229d77eaa72539f1571f0fdc186d6b1e6d545c3b7b334147551281_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-ironic-hardware-inventory-recorder-rhel8@sha256:7a7503a9ed229d77eaa72539f1571f0fdc186d6b1e6d545c3b7b334147551281_amd64
Red Hatopenshift4/ose-cluster-machine-approver@sha256:be05464a9bbd5529a0211da8ee50484136fd96153415227fea10d7a5cd7d7c82_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-cluster-machine-approver@sha256:be05464a9bbd5529a0211da8ee50484136fd96153415227fea10d7a5cd7d7c82_amd64
Red Hatopenshift4/ose-aws-machine-controllers@sha256:e76b927f3c4c8d22f62917f90b3967f0e5e0489a0fe1293cee25afbebdf2882e_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-aws-machine-controllers@sha256:e76b927f3c4c8d22f62917f90b3967f0e5e0489a0fe1293cee25afbebdf2882e_amd64
Red Hatopenshift4/ose-installer@sha256:85f2c49d05b0cc7f00dad42cb81353bc4f180aa2bede05cacc5ab0823eedaa1a_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-installer@sha256:85f2c49d05b0cc7f00dad42cb81353bc4f180aa2bede05cacc5ab0823eedaa1a_amd64
Red Hatopenshift4/ose-jenkins@sha256:d299224826d02c74ae01359670eb8f1d9ad648d19fbce951edf18e6f48d0d245_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-jenkins@sha256:d299224826d02c74ae01359670eb8f1d9ad648d19fbce951edf18e6f48d0d245_amd64
Red Hatopenshift4/ose-local-storage-operator@sha256:e2b564930a22b918fb8c79bded57d0dc6438e2a112d4e1b48db0223d5b664bcf_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-local-storage-operator@sha256:e2b564930a22b918fb8c79bded57d0dc6438e2a112d4e1b48db0223d5b664bcf_amd64
Red Hatopenshift4/ose-template-service-broker-operator@sha256:33cd509ae8c3ba9ceeb8fe4e52addda5fd65bd815b549b43698b3db45a8fe676_amd64 as a component of Red Hat OpenShift Container Platform 4.3*
Red Hatopenshift4/ose-cluster-network-operator@sha256:ec2ca13fff99d6ee9ef9a5a24465dd3a7a10f83e97e65afe059eba640bf04b93_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-cluster-network-operator@sha256:ec2ca13fff99d6ee9ef9a5a24465dd3a7a10f83e97e65afe059eba640bf04b93_amd64
Red Hatopenshift4/ose-prometheus-operator@sha256:b3c9e54610075e7b7096c2b35a50bd9f21de6d18d735ce10a460f29b50a72f35_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-prometheus-operator@sha256:b3c9e54610075e7b7096c2b35a50bd9f21de6d18d735ce10a460f29b50a72f35_amd64
Red Hatopenshift4/ose-ironic-ipa-downloader-rhel8@sha256:443d984b2a166b7194db3e5de76832c831a2b0fb2a24b7d81e88f9714676412f_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-ironic-ipa-downloader-rhel8@sha256:443d984b2a166b7194db3e5de76832c831a2b0fb2a24b7d81e88f9714676412f_amd64

…and 110 more

Timeline

  • Feb 19, 2020 CVE Published
  • Mar 3, 2026 CVE Updated
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›