CVE-2020-8945: Use After Free
A use-after-free vulnerability was found in the Go GPGME wrapper library, github.com/proglottis/gpgme. An attacker could use this flaw to crash or cause potential code execution in Go applications that use this library, under certain conditions, during GPG signature verification.
Other sources
The Go wrapper for the GPGME library, github.com/proglottis/gpgme (and fork github.com/mtrmac/gpgme), vendored into github.com/containers/image, is susceptible, under certain conditions, to a use-after-free when used during container image pulls by tools like docker and cri-o.
Upstream Fix:
https://github.com/proglottis/gpgme/pull/23
— Red Hat
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1:0.1.40-7.el7_8 - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 0:1.11.6-8.el7_8 - Upgrade
Upgrade
redhat/dockerto a version that resolves this vulnerability.Fixed in 2:1.13.1-161.git64e9980.el7_8 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 0:1.6.4-18.el7_8 - Upgrade
Upgrade
redhat/atomic-openshiftto a version that resolves this vulnerability.Fixed in 0:3.11.248-1.git.0.92ee8ac.el7 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1:0.1.32-6.git1715c90.el8_0 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1:0.1.32-7.git1715c90.rhaos4.2.el8 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.2.32-202005020632.git.1.1b0fab9.el8 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.16.4-1.dev.rhaos4.3.git9238eee.el7 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.3.7-202003130552.git.0.6027a27.el8 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1:0.1.40-4.rhaos.el8 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 0:1.6.4-10.rhaos4.3.el8 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.17.4-8.dev.rhaos4.4.git5f5c5e4.el8 - Upgrade
Upgrade
redhat/machine-config-daemonto a version that resolves this vulnerability.Fixed in 0:4.4.0-202007092124.p0.git.2349.08d34d1.el8 - Upgrade
Upgrade
redhat/machine-config-daemonto a version that resolves this vulnerability.Fixed in 0:4.5.0-202007012112.p0.git.2527.d12c3da.el8 - Upgrade
Upgrade
redhat/proglottis/gpgmeto a version that resolves this vulnerability.Fixed in 0.1.1 - Upgrade
Upgrade
github.com/proglottis/gpgmeto a version that resolves this vulnerability.Fixed in 0.1.1 - Upgrade
Upgrade
github.com/mtrmac/gpgmeto a version that resolves this vulnerability.Fixed in 0.1.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-8945?
CVE-2020-8945 is a use-after-free vulnerability found in the Go GPGME wrapper library, github.com/proglottis/gpgme.
What is the severity level of CVE-2020-8945?
The severity level of CVE-2020-8945 is high with a CVSS score of 7.5.
How does CVE-2020-8945 impact Go applications?
CVE-2020-8945 can cause crashes or potential code execution in Go applications that use the vulnerable Go GPGME wrapper library.
Which versions of the proglottis/gpgme library are affected by CVE-2020-8945?
Versions up to and excluding 0.1.1 of the proglottis/gpgme library are affected by CVE-2020-8945.
Where can I find more information about CVE-2020-8945?
You can find more information about CVE-2020-8945 at the following references: [Link 1](https://github.com/proglottis/gpgme/pull/23), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1802897), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1802898).