Описание
In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.
A flaw was found in Go, where it attempts to allocate excessive memory. This issue may cause panic or unrecoverable fatal error if passed inputs with very large exponents. The highest threat from this vulnerability is to system availability.
Отчет
- Since OpenShift Container Platform 3.11 is in Maintenance Phase of the support, only Important and Critical severity vulnerabilities will be addressed at this time.
- In Service Telemetry Framework, because the flaw has a lower impact and the package is not directly used by STF, no updates will be provided at this time for the STF containers.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
OpenShift Serverless | knative-eventing | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh-operator | Will not fix | ||
OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | ||
Red Hat Ceph Storage 2 | golang | Out of support scope | ||
Red Hat Ceph Storage 2 | grafana | Out of support scope | ||
Red Hat Ceph Storage 3 | golang | Out of support scope | ||
Red Hat Ceph Storage 3 | golang-github-prometheus-node_exporter | Out of support scope | ||
Red Hat Ceph Storage 3 | grafana | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.
In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.
In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic fo ...
Go before 1.15.12 and 1.16.x before 1.16.5 attempts to allocate excessive memory (issue 2 of 2).
EPSS
7.5 High
CVSS3