VDB
RHSA-2021:0980
RHSA-2021:0980
PUBLISHED
CVSS 7.5 HIGH
A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vulnerability. If an attacker is able to supply specific characters or strings to the vulnerable application, there is the potential to cause an infinite loop to occur using more memory, resulting in a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 | |
| Red Hat | rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8 | rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 |
| Red Hat | rhacm2/acm-must-gather-rhel8@sha256:0b5db239e2eee0bc73f60910953a16b3abd4e2823d55f6fcfbc3f1d4fadbe564_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8 | *, * |
Timeline
- Mar 24, 2021 CVE Published
- Apr 25, 2026 Distribution Patch
- May 4, 2026 CVE Updated
- May 20, 2026 Distribution Patch
- May 20, 2026 Security Advisory
- May 20, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1853652 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1925281 issue
- https://www.cve.org/CVERecord?id=CVE-2020-14040 advisory
- https://groups.google.com/forum/#!topic/golang-announce/bXVeAmGOqz0 advisory
- https://access.redhat.com/security/cve/CVE-2020-14040 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1903446 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1920654 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1931887 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1932430 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0980.json advisory
- https://github.com/golang/go/issues/39491 advisory
- https://access.redhat.com/errata/RHSA-2021:0980 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-14040 advisory