VDB
RHSA-2022%3A0655
RHSA-2022%3A0655
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was found in archive/zip of the Go standard library. Applications written in Go can panic or potentially exhaust system memory when parsing malformed ZIP files. An attacker capable of submitting a crafted ZIP file to a Go application using archive/zip to process that file could cause a denial of service via memory exhaustion or panic. This particular flaw is an incomplete fix for a previous flaw.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-ovn-kubernetes@sha256:61aec5d4bccb68ec425cabfbaa3add71ef9354391386bfc599f5b837e8ac3a19_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | * |
| Red Hat | openshift4/ose-jenkins-agent-nodejs-12-rhel8@sha256:c91e236a0d9b7f0d6951d524081d35d939c5a4226b5dd9e94d8a9f46f888c781_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-jenkins-agent-nodejs-12-rhel8@sha256:c91e236a0d9b7f0d6951d524081d35d939c5a4226b5dd9e94d8a9f46f888c781_arm64 |
| Red Hat | openshift4/ose-ovn-kubernetes@sha256:73bc212a2b46ba476033019791bd7cacaf3fadcd605601e1640a983742cf64c4_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | * |
| Red Hat | openshift4/ose-installer@sha256:1d418a5550c3a42102958325d2dc0cd85924379282118ec8ddae5768c149eb57_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-installer@sha256:1d418a5550c3a42102958325d2dc0cd85924379282118ec8ddae5768c149eb57_arm64 |
| Red Hat | openshift4/ose-jenkins-agent-nodejs-12-rhel8@sha256:7b7c083f4e3405971db7c63b4f0a5695a93276b551b8433ca9a1b492a7b8bd4e_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-jenkins-agent-nodejs-12-rhel8@sha256:7b7c083f4e3405971db7c63b4f0a5695a93276b551b8433ca9a1b492a7b8bd4e_amd64 |
| Red Hat | openshift4/ose-cluster-monitoring-operator@sha256:37800a9c1017dacab96ed52727b3bfa90b965fd5712abfa5fdadabb21c7cfa66_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-cluster-monitoring-operator@sha256:37800a9c1017dacab96ed52727b3bfa90b965fd5712abfa5fdadabb21c7cfa66_arm64 |
| Red Hat | openshift4/ose-jenkins-agent-maven@sha256:21c005009ff61ca1c3e815e0ea8c676c53a2b1a0cbb4f9c83ee9eec7781d76a4_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-jenkins-agent-maven@sha256:21c005009ff61ca1c3e815e0ea8c676c53a2b1a0cbb4f9c83ee9eec7781d76a4_amd64 |
| Red Hat | openshift4/ose-tools-rhel8@sha256:f222e8e4a4e99fea5548b95381e026807dd64beb272376e454c10b9f5b17861b_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-tools-rhel8@sha256:f222e8e4a4e99fea5548b95381e026807dd64beb272376e454c10b9f5b17861b_amd64 |
| Red Hat | openshift4/ose-cli-alt-rhel8@sha256:86935754535e107ef5b1d53e417df76289f1d8aaaa53b4e2235e8715fdcaf58e_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-cli-alt-rhel8@sha256:86935754535e107ef5b1d53e417df76289f1d8aaaa53b4e2235e8715fdcaf58e_amd64 |
| Red Hat | openshift4/ose-installer@sha256:1e9ec7bb9041f78635f72ea89dca762a38d4bdad9cc8570fb2ef5eda23da6afb_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-installer@sha256:1e9ec7bb9041f78635f72ea89dca762a38d4bdad9cc8570fb2ef5eda23da6afb_ppc64le |
| Red Hat | openshift4/ose-jenkins-agent-maven@sha256:02ede27ec4455daac0542dc78299cb655b60d0d604eec22af50ae0f75c48154e_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-jenkins-agent-maven@sha256:02ede27ec4455daac0542dc78299cb655b60d0d604eec22af50ae0f75c48154e_ppc64le |
| Red Hat | openshift4/ose-jenkins-agent-maven@sha256:92ec94b8d98ac498251164556a1c82907ea5c0fba1921711288313daa2c913f5_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | * |
| Red Hat | openshift4/ose-deployer@sha256:3e84917a7bab503493b592b7224c9d3876e570a9fd1777dbf9e5ae20de297494_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-deployer@sha256:3e84917a7bab503493b592b7224c9d3876e570a9fd1777dbf9e5ae20de297494_ppc64le |
| Red Hat | openshift4/ose-must-gather@sha256:da47acb4ac4c86d8ec19ec35aaa64ff84277e0d646f8e6d13c05b80c1c826f6b_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-must-gather@sha256:da47acb4ac4c86d8ec19ec35aaa64ff84277e0d646f8e6d13c05b80c1c826f6b_arm64 |
| Red Hat | openshift4/ose-machine-config-operator@sha256:10c600a9e5d935d693ee595d543c81a9f292d6ea2620895af36030c6c2945da4_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-machine-config-operator@sha256:10c600a9e5d935d693ee595d543c81a9f292d6ea2620895af36030c6c2945da4_arm64 |
| Red Hat | openshift4/ose-tests@sha256:12f90a7589521f3b5dbf5715c752edbeaffb22bfd78e16fbd7d184e6330cb58e_s390x as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-tests@sha256:12f90a7589521f3b5dbf5715c752edbeaffb22bfd78e16fbd7d184e6330cb58e_s390x |
| Red Hat | openshift4/ose-deployer@sha256:624896e504b4a672507e9f04ed77c63732666704543349568dd71842e9c63111_s390x as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-deployer@sha256:624896e504b4a672507e9f04ed77c63732666704543349568dd71842e9c63111_s390x |
| Red Hat | openshift4/ose-tests@sha256:733d3576f8be767339e3dbf57a4b299f4e92ba9c743bcd023ebc3f1dd8afdae7_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-tests@sha256:733d3576f8be767339e3dbf57a4b299f4e92ba9c743bcd023ebc3f1dd8afdae7_arm64 |
| Red Hat | openshift4/ose-deployer@sha256:8a163dfa65b43d2eae1a05d18b62c04f312d3c660f77103b799fa3f41555252d_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-deployer@sha256:8a163dfa65b43d2eae1a05d18b62c04f312d3c660f77103b799fa3f41555252d_arm64 |
| Red Hat | openshift4/ose-cli@sha256:4522ddf917d1b704edb693980ec439d4a45a838963e1f89b2d75f1d451ee5350_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-cli@sha256:4522ddf917d1b704edb693980ec439d4a45a838963e1f89b2d75f1d451ee5350_ppc64le |
…and 62 more
Timeline
- Feb 28, 2022 CVE Published
- Mar 20, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:0655 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1996751 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2006044 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2014003 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2038406 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2040530 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2040594 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2050271 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2050911 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2052307 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2052553 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2052710 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2052929 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2053149 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2053581 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2054139 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2054608 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2055100 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2056631 issue
…and 7 more