CVE Vulnerabilities

CVE-2020-29652

NULL Pointer Dereference

Published: Dec 17, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
SshGolang*0.0.0-20201203163018-be400aefbc4c (including)
Red Hat Enterprise Linux 8RedHatcontainer-tools:rhel8-8040020210407081426.59631bd5*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-aws-ebs-csi-driver-rhel8:v4.7.0-202102130115.p0*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-azure-machine-controllers:v4.7.0-202102130115.p0*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-baremetal-installer-rhel8:v4.7.0-202102130115.p0*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-installer:v4.7.0-202102130115.p0*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-installer-artifacts:v4.7.0-202102130115.p0*
RHEL-8-CNV-4.8RedHatcontainer-native-virtualization/kubernetes-nmstate-handler-rhel8:v4.8.0-21*
RHEL-8-CNV-4.8RedHatcontainer-native-virtualization/kubevirt-v2v-conversion:v4.8.0-10*
RHEL-8-CNV-4.8RedHatcontainer-native-virtualization/kubevirt-vmware:v4.8.0-11*
RHEL-8-CNV-4.8RedHatcontainer-native-virtualization/node-maintenance-operator:v4.8.0-19*
RHEL-8-CNV-4.8RedHatcontainer-native-virtualization/vm-import-controller:v4.8.0-18*
RHEL-8-CNV-4.8RedHatcontainer-native-virtualization/vm-import-controller-rhel8:v4.8.0-18*
RHEL-8-CNV-4.8RedHatcontainer-native-virtualization/vm-import-operator-rhel8:v4.8.0-18*
RHEL-8-CNV-4.8RedHatcontainer-native-virtualization/vm-import-virtv2v-rhel8:v4.8.0-18*
Golang-go.cryptoUbuntudevel*
Golang-go.cryptoUbuntuesm-apps/focal*
Golang-go.cryptoUbuntuesm-apps/jammy*
Golang-go.cryptoUbuntuesm-apps/noble*
Golang-go.cryptoUbuntufocal*
Golang-go.cryptoUbuntugroovy*
Golang-go.cryptoUbuntuhirsute*
Golang-go.cryptoUbuntuimpish*
Golang-go.cryptoUbuntujammy*
Golang-go.cryptoUbuntukinetic*
Golang-go.cryptoUbuntulunar*
Golang-go.cryptoUbuntumantic*
Golang-go.cryptoUbuntunoble*
Golang-go.cryptoUbuntuoracular*
Golang-go.cryptoUbuntuplucky*
Golang-go.cryptoUbuntuquesting*
Golang-go.cryptoUbuntuupstream*
KubernetesUbuntufocal*
KubernetesUbuntugroovy*
KubernetesUbuntuhirsute*
KubernetesUbuntuimpish*
KubernetesUbuntukinetic*
KubernetesUbuntulunar*
KubernetesUbuntumantic*
KubernetesUbuntuoracular*
SnapdUbuntutrusty*

Potential Mitigations

References