Описание
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
A flaw was found in Golang. Processing an incomplete post-handshake message for a QUIC connection caused a panic.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Not affected | ||
Cost Management Metrics Operator | costmanagement/costmanagement-metrics-rhel8-operator | Affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel8 | Not affected | ||
Logical Volume Manager Storage | lvms4/topolvm-rhel9 | Affected | ||
mirror registry for Red Hat OpenShift | mirror-registry-container | Will not fix | ||
Node HealthCheck Operator | workload-availability/node-healthcheck-rhel8-operator | Will not fix | ||
Node Maintenance Operator | workload-availability/node-maintenance-rhel8-operator | Affected | ||
OpenShift Developer Tools and Services | helm | Affected | ||
OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Affected | ||
OpenShift Pipelines | openshift-pipelines-client | Affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2237777golang: crypto/tls: panic when processing post-handshake message on QUIC connections
EPSS
Процентиль: 12%
0.00041
Низкий
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 2 года назад
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
CVSS3: 7.5
nvd
почти 2 года назад
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
CVSS3: 7.5
debian
почти 2 года назад
Processing an incomplete post-handshake message for a QUIC connection ...
CVSS3: 7.5
github
почти 2 года назад
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
CVSS3: 7.5
fstec
почти 2 года назад
Уязвимость функции HandleData() пакета crypto/tls языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
Процентиль: 12%
0.00041
Низкий
7.5 High
CVSS3