Back

HIGH

golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag

Published Jan 2, 2021

Description

In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

Affected products

Remediation

Red Hat statement

Below Red Hat products include the affected version of 'golang.org/x/text', however the language package is not being used and hence they are rated as having a security impact of Low. A future update may address this issue. * Red Hat OpenShift Container Storage 4 * OpenShift ServiceMesh (OSSM) * Red Hat Gluster Storage 3 * Windows Container Support for Red Hat OpenShift Only three components in OpenShift Container Platform include the affected package, 'golang.org/x/text/language' , the installer, baremetal installer and thanos container images. All other components that include a version of 'golang.org/x/text' do not include the 'language' package and are therefore not affected.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 2, 2021
Updated Aug 4, 2024
Reserved Nov 16, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 2, 2021
ENISA EUVD
Assigner mitre
Published Jan 2, 2021
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-21244