VDB
RHSA-2021%3A0980
RHSA-2021%3A0980
PUBLISHED
CVSS 7.5 HIGH
A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vulnerability. If an attacker is able to supply specific characters or strings to the vulnerable application, there is the potential to cause an infinite loop to occur using more memory, resulting in a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 | |
| Red Hat | rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8 | rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 |
| Red Hat | rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8 | *, * |
Timeline
- Mar 24, 2021 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 4, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2021:0980 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/security/cve/CVE-2020-14040 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1853652 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1903446 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1920654 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1925281 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1931887 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1932430 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0980.json advisory
- https://www.cve.org/CVERecord?id=CVE-2020-14040 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-14040 advisory
- https://github.com/golang/go/issues/39491 advisory
- https://groups.google.com/forum/#!topic/golang-announce/bXVeAmGOqz0 advisory