golang: invalid public key causes panic in dsa.Verify
Published Oct 24, 2019
7.5
HIGHCVSS 3.1
EPSS 4.69%
Description
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Affected products
No data.
Configuration 1
Configuration 2
- 9.0
- 10.0
Configuration 3
- 30
- 31
Configuration 4
- 1.0
- 8.0
- 8.1
Configuration 6
- ≥ 2018.1.0 · ≤ 2018.2.3
- 2019.1.0
- 2019.1.1
- 2019.1.2
- ≤ 1.7.2
- ≤ 4.23.1f
- ≤ 0.25
No data.
Red Hat Developer Tools
go-toolset-1.12-0:1.12.12-4.el7
Fixed · RHSA-2020:0101
Red Hat Developer Tools
go-toolset-1.12-golang-0:1.12.12-4.el7
Fixed · RHSA-2020:0101
Red Hat Enterprise Linux 8
go-toolset:rhel8-8010020191220185136.0ed30617
Fixed · RHSA-2020:0329
Red Hat OpenShift Container Platform 4.3
cri-o-0:1.16.2-13.dev.rhaos4.3.gita83f883.el7
Fixed · RHBA-2020:0390
Red Hat OpenShift Container Platform 4.3
openshift-0:4.3.1-202001310552.git.0.331f390.el7
Fixed · RHBA-2020:0390
Red Hat OpenShift Container Platform 4.3
openshift-clients-0:4.3.1-202001310552.git.1.075d46a.el7
Fixed · RHBA-2020:0390
Red Hat Ceph Storage 2
golang
Out of support scope
Red Hat Ceph Storage 3
golang
Will not fix
Red Hat Ceph Storage 3
grafana
Not affected
Red Hat Enterprise Linux 7
golang
Out of support scope
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Out of support scope
Red Hat Storage 3
golang
Affected
Red Hat Storage 3
grafana
Not affected
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Tools | go-toolset-1.12-0:1.12.12-4.el7 | Fixed | RHSA-2020:0101 |
| Red Hat Developer Tools | go-toolset-1.12-golang-0:1.12.12-4.el7 | Fixed | RHSA-2020:0101 |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8-8010020191220185136.0ed30617 | Fixed | RHSA-2020:0329 |
| Red Hat OpenShift Container Platform 4.3 | cri-o-0:1.16.2-13.dev.rhaos4.3.gita83f883.el7 | Fixed | RHBA-2020:0390 |
| Red Hat OpenShift Container Platform 4.3 | openshift-0:4.3.1-202001310552.git.0.331f390.el7 | Fixed | RHBA-2020:0390 |
| Red Hat OpenShift Container Platform 4.3 | openshift-clients-0:4.3.1-202001310552.git.1.075d46a.el7 | Fixed | RHBA-2020:0390 |
| Red Hat Ceph Storage 2 | golang | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | golang | Will not fix | n/a |
| Red Hat Ceph Storage 3 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 7 | golang | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Out of support scope | n/a |
| Red Hat Storage 3 | golang | Affected | n/a |
| Red Hat Storage 3 | grafana | Not affected | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
stdlib
Go
Introduced 0 Fixed 1.12.11stdlib
Go
Introduced 1.13.0-0 Fixed 1.13.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | stdlib | 0 | 1.12.11 |
| Go | stdlib | 1.13.0-0 | 1.13.2 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.69% (0.04693) | 91.51th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.69% (0.04693) | 90.59th | v5 (v2026.06.15) |
| Nov 21, 2025 | 2.34% (0.02340) | 84.34th | v4 (v2025.03.14) |
| Nov 18, 2025 | 7.70% (0.07704) | 91.03th | v4 (v2025.03.14) |
| Aug 9, 2025 | 2.34% (0.02340) | 84.22th | v4 (v2025.03.14) |
| Jun 24, 2025 | 4.06% (0.04061) | 88.02th | v4 (v2025.03.14) |
| Jun 21, 2025 | 2.32% (0.02319) | 84.08th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.92% (0.05915) | 89.67th | v4 (v2025.03.14) |
| Mar 29, 2025 | 17.60% (0.17601) | 91.90th | v4 (v2025.03.14) |
| Mar 28, 2025 | 5.92% (0.05915) | 89.68th | v4 (v2025.03.14) |
| Mar 27, 2025 | 17.60% (0.17601) | 94.23th | v4 (v2025.03.14) |
| Mar 20, 2025 | 5.92% (0.05915) | 89.78th | v4 (v2025.03.14) |
| Mar 19, 2025 | 17.60% (0.17601) | 94.33th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.92% (0.05915) | 89.92th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.37% (0.00368) | 73.39th | v3 (v2023.03.01) |
| Feb 17, 2024 | 0.41% (0.00414) | 73.36th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.59% (0.00591) | 75.82th | v3 (v2023.03.01) |
| Sep 14, 2023 | 0.57% (0.00573) | 75.22th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.67% (0.00667) | 76.56th | v3 (v2023.03.01) |
| Mar 6, 2023 | 23.44% (0.23437) | 96.70th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.44% (0.23437) | 94.77th | v2 (v2022.01.01) |
| Feb 3, 2022 | 11.74% (0.11741) | 88.45th | v1 |
| Jan 6, 2022 | 11.74% (0.11741) | 88.31th | v1 |
| Nov 9, 2021 | 11.74% (0.11741) | 95.76th | v1 |
| Sep 1, 2021 | 10.99% (0.10990) | 95.28th | v1 |
| Apr 14, 2021 | 10.99% (0.10990) | 0.00th | v1 |
References (18)
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00043.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00044.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0101 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0329 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-17596 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1763310 Issue Tracking
- https://github.com/golang/go/issues/34960 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://groups.google.com/d/msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJ x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://groups.google.com/forum/#!msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJ
- https://lists.debian.org/debian-lts-announce/2021/03/msg00014.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00015.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VS3HPSE25ZSGS4RSOTADC67YNOHIGVV/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVOWGM7IQGRO7DS2MCUMYZRQ4TYOZNAS/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-17596
- https://security.netapp.com/advisory/ntap-20191122-0005/ x_refsource_CONFIRMThird Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/10134-security-advisory-46 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-17596
- https://www.debian.org/security/2019/dsa-4551 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.