VDB
RHSA-2020%3A3783
RHSA-2020%3A3783
PUBLISHED
CVSS 7.5 HIGH
A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vulnerability. If an attacker is able to supply specific characters or strings to the vulnerable application, there is the potential to cause an infinite loop to occur using more memory, resulting in a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-cluster-network-operator@sha256:2d495698c6d486a5c1dbb64e98cba9caa00e8ef322122d57e64b7e510d63b400_ppc64le as a component of Red Hat OpenShift Container Platform 4.4 | *, * |
| Red Hat | openshift4/ose-cluster-network-operator@sha256:0f5a789e430e785c100f301aca31b7d0985ed16a9312926f55bc7d201ad03d36_s390x as a component of Red Hat OpenShift Container Platform 4.4 | openshift4/ose-cluster-network-operator@sha256:0f5a789e430e785c100f301aca31b7d0985ed16a9312926f55bc7d201ad03d36_s390x |
| Red Hat | openshift4/ose-cluster-network-operator@sha256:16292a84aae8d6b9cb9840f543324d5c42d33eeed394c8556011f26dc4486ac0_amd64 as a component of Red Hat OpenShift Container Platform 4.4 | openshift4/ose-cluster-network-operator@sha256:16292a84aae8d6b9cb9840f543324d5c42d33eeed394c8556011f26dc4486ac0_amd64, * |
| Red Hat | openshift4/ose-cluster-network-operator@sha256:2d495698c6d486a5c1dbb64e98cba9caa00e8ef322122d57e64b7e510d63b400_ppc64le as a component of Red Hat OpenShift Container Platform 4.4 | openshift4/ose-cluster-network-operator@sha256:2d495698c6d486a5c1dbb64e98cba9caa00e8ef322122d57e64b7e510d63b400_ppc64le |
| Red Hat | openshift4/ose-cluster-network-operator@sha256:16292a84aae8d6b9cb9840f543324d5c42d33eeed394c8556011f26dc4486ac0_amd64 as a component of Red Hat OpenShift Container Platform 4.4 | openshift4/ose-cluster-network-operator@sha256:16292a84aae8d6b9cb9840f543324d5c42d33eeed394c8556011f26dc4486ac0_amd64 |
| Red Hat | openshift4/ose-cluster-network-operator@sha256:0f5a789e430e785c100f301aca31b7d0985ed16a9312926f55bc7d201ad03d36_s390x as a component of Red Hat OpenShift Container Platform 4.4 | *, * |
Timeline
- Sep 22, 2020 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- May 4, 2026 CVE Updated
- May 20, 2026 Distribution Patch
- May 20, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1853652 issue
- https://access.redhat.com/security/cve/CVE-2020-14040 advisory
- https://groups.google.com/forum/#!topic/golang-announce/bXVeAmGOqz0 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3783.json advisory
- https://www.cve.org/CVERecord?id=CVE-2020-14040 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-14040 advisory
- https://github.com/golang/go/issues/39491 advisory
- https://access.redhat.com/errata/RHSA-2020:3783 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory