CVE-2020-28852: Out-of-bounds Read
A flaw was found in golang.org. In x/text, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag.
Other sources
In x/text in Go 1.15.4, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. x/text/language is supposed to be able to parse an HTTP Accept-Language header.
Upstream issue:
https://github.com/golang/go/issues/42536
— Red Hat
In x/text in Go before v0.3.5 a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)
— Microsoft
In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-28852?
CVE-2020-28852 is a vulnerability in golang.org/x/text that allows for a "slice bounds out of range" panic.
How severe is CVE-2020-28852?
CVE-2020-28852 has a severity rating of 7.5 (high).
Which software is affected by CVE-2020-28852?
The software affected by CVE-2020-28852 includes golang.org/x/text versions up to and exclusive 0.3.5, servicemesh versions up to and exclusive 0:2.0.9-3.el8, git-lfs versions up to and exclusive 0:2.13.3-3.el8_6, and podman versions up to and exclusive 2:4.2.0-3.el9.
How do I fix CVE-2020-28852?
To fix CVE-2020-28852, update the affected software to the recommended version, such as golang.org/x/text version 0.3.5.
Where can I find more information about CVE-2020-28852?
You can find more information about CVE-2020-28852 in the references provided: [GitHub Issue](https://github.com/golang/go/issues/42536), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1913365), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1913364).