CVE-2020-15586: Race Condition
A flaw was found Go's net/http package. Servers using ReverseProxy from net/http in the Go standard library are vulnerable to a data race that results in a denial of service. The highest threat from this vulnerability is to system availability.
Other sources
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers as demonstrated by the httputil.ReverseProxy Handler because it reads a request body and writes a response at the same time.
— Microsoft
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
Golang Go is vulnerable to a denial of service, caused by a data race in some net/http servers. By sending specially-crafted HTTP requests, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Servers where the Handler concurrently reads the request body and writes a response can encounter a data race and crash. The httputil.ReverseProxy Handler is affected.
References: https://github.com/golang/go/issues/34902 https://groups.google.com/forum/?utmmedium=email&utmsource=footer#!msg/golang-announce/XZNfaiwgt2w/E6gHDs32AQAJ
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/golang-1.11to a version that resolves this vulnerability.Fixed in 1.11.6-1+deb10u4Fixed in 1.11.6-1+deb10u7 - Upgrade
Upgrade
debian/golang-1.15to a version that resolves this vulnerability.Fixed in 1.15.15-1~deb11u4 - Upgrade
Upgrade
redhat/iorto a version that resolves this vulnerability.Fixed in 0:1.1.11-2.el8 - Upgrade
Upgrade
redhat/servicemeshto a version that resolves this vulnerability.Fixed in 0:1.1.11-2.el8 - Upgrade
Upgrade
redhat/servicemesh-cnito a version that resolves this vulnerability.Fixed in 0:1.1.11-2.el8 - Upgrade
Upgrade
redhat/servicemesh-grafanato a version that resolves this vulnerability.Fixed in 0:6.4.3-19.el8 - Upgrade
Upgrade
redhat/servicemesh-operatorto a version that resolves this vulnerability.Fixed in 0:1.1.11-3.el8 - Upgrade
Upgrade
redhat/servicemesh-prometheusto a version that resolves this vulnerability.Fixed in 0:2.14.0-20.el8 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.13-0:1.13.15-1.el7 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.13-golang-0:1.13.15-3.el7 - Upgrade
Upgrade
redhat/faqto a version that resolves this vulnerability.Fixed in 0:0.0.6-5.el7 - Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 0:4.4.0-202011130111.p0.git.0.4861dfa.el7 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.4.0-202011122017.p0.git.3445.6937a03.el7 - Upgrade
Upgrade
redhat/atomic-enterprise-service-catalogto a version that resolves this vulnerability.Fixed in 1:4.5.0-202010081312.p0.git.1808.498e523.el7 - Upgrade
Upgrade
redhat/atomic-openshift-service-idlerto a version that resolves this vulnerability.Fixed in 0:4.5.0-202010081312.p0.git.15.d7814b2.el7 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.18.4-4.rhaos4.5.git6dee389.el8 - Upgrade
Upgrade
redhat/apbto a version that resolves this vulnerability.Fixed in 0:2.0.3-3.el7 - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 0:1.11.6-9.rhaos4.5.el8 - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0:0.8.6-2.rhaos4.5.el8 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.18.4-7.rhaos4.5.git572d9f7.el7 - Upgrade
Upgrade
redhat/cri-toolsto a version that resolves this vulnerability.Fixed in 0:1.18.0-4.el8 - Upgrade
Upgrade
redhat/golang-github-prometheus-promuto a version that resolves this vulnerability.Fixed in 0:0.5.0-3.git642a960.el7 - Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102261511.p0.git.0.f0229b9.el8 - Upgrade
Upgrade
redhat/ignitionto a version that resolves this vulnerability.Fixed in 0:0.35.1-12.rhaos4.5.gitb4d18ad.el8 - Upgrade
Upgrade
redhat/kubefed-clientto a version that resolves this vulnerability.Fixed in 0:4.5.0-202002271711.git.2.3bd46d6.el7 - Upgrade
Upgrade
redhat/openshift-eventrouterto a version that resolves this vulnerability.Fixed in 0:0.2-5.git7c289cc.el7 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 0:1.9.3-2.rhaos4.5.el8 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1:1.1.1-2.rhaos4.5.el8 - Upgrade
Upgrade
redhat/machine-config-daemonto a version that resolves this vulnerability.Fixed in 0:4.5.0-202012050338.p0.git.2581.e7a62a7.el8 - Upgrade
Upgrade
redhat/ignitionto a version that resolves this vulnerability.Fixed in 0:2.6.0-5.rhaos4.6.git947598e.el8 - Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 0:4.6.0-202010022112.p0.git.94033.ef41184.el7 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.6.0-202010081244.p0.git.3794.4743d24.el8 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 0:1.9.3-3.rhaos4.6.el8 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1:1.1.1-3.rhaos4.6.el8 - Upgrade
Upgrade
redhat/openshift-eventrouterto a version that resolves this vulnerability.Fixed in 0:0.2-6.git7c289cc.el8 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.20.2-12.rhaos4.7.git9f7be76.el7 - Upgrade
Upgrade
redhat/cri-toolsto a version that resolves this vulnerability.Fixed in 0:1.20.0-3.el7 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2-plugins-0:4.7.1621361158-1.el8 - Upgrade
Upgrade
redhat/redhat-release-coreosto a version that resolves this vulnerability.Fixed in 0:47.83-2.el8 - Upgrade
Upgrade
redhat/golang-github-prometheus-promuto a version that resolves this vulnerability.Fixed in 0:0.5.0-3.git642a960.el8 - Upgrade
Upgrade
redhat/mcgto a version that resolves this vulnerability.Fixed in 0:5.6.0-39.2279a46.5.6.el8 - Upgrade
Upgrade
redhat/kubevirtto a version that resolves this vulnerability.Fixed in 0:4.9.0-287.el8 - Upgrade
Upgrade
redhat/Goto a version that resolves this vulnerability.Fixed in 1.14.5 - Upgrade
Upgrade
redhat/Goto a version that resolves this vulnerability.Fixed in 1.13.13 - Upgrade
Upgrade
redhat/Goto a version that resolves this vulnerability.Fixed in 1.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.15.13-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.16.2-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.16.2-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2021:1515
- RHSA-2021:0072
- RHSA-2020:5649
- RHSA-2020:4214
- RHSA-2020:3665
- RHBA-2020:5123
- RHBA-2020:4229
- RHSA-2020:5118
- RHSA-2020:5119
- RHSA-2021:0713
- RHSA-2021:1016
- RHBA-2020:5356
- RHBA-2020:4197
- RHSA-2020:4297
- RHSA-2021:0172
- RHSA-2021:0956
- RHSA-2021:2122
- RHSA-2021:1366
- RHSA-2020:5605
- RHSA-2020:5606
- RHSA-2021:0799
- RHSA-2020:4201
- RHSA-2021:4103
- IBM-6403463
Frequently Asked Questions
What is the severity of CVE-2020-15586?
CVE-2020-15586 is classified as a denial of service vulnerability due to a data race in some net/http servers.
How do I fix CVE-2020-15586?
To fix CVE-2020-15586, upgrade to Go version 1.13.13, 1.14.5, or later versions.
Which packages are affected by CVE-2020-15586?
CVE-2020-15586 affects various versions of the Go programming language and its implementations in multiple deployment environments.
What are the potential impacts of CVE-2020-15586?
Exploitation of CVE-2020-15586 can lead to a denial of service condition affecting the stability and availability of the affected services.
Is there a workaround for CVE-2020-15586 if I cannot upgrade?
There are no specific workarounds for CVE-2020-15586 other than applying the available patches through software updates.