proglottis/gpgme: Use-after-free in GPGME bindings during container image pull
Published Feb 12, 2020
7.5
HIGHCVSS 3.1
EPSS 5.07%
Description
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
Affected products
No data.
Configuration 1
- < 0.1.1
Configuration 2
- 3.11
- 4.1
- 4.2
- 4.3
- 4.4
- 4.5
- 4.1
- 4.2
- 4.1
- 4.2
Running on/with
- 7.0
- 8.0
Configuration 3
- 30
- 31
- 32
Configuration 4
- 7.0
- 7.0
- 7.0
- 7.0
Configuration 5
- 3.11
No data.
Red Hat Enterprise Linux 7 Extras
buildah-0:1.11.6-8.el7_8
Fixed · RHSA-2020:1231
Red Hat Enterprise Linux 7 Extras
docker-2:1.13.1-161.git64e9980.el7_8
Fixed · RHSA-2020:1234
Red Hat Enterprise Linux 7 Extras
podman-0:1.6.4-18.el7_8
Fixed · RHSA-2020:2117
Red Hat Enterprise Linux 7 Extras
skopeo-1:0.1.40-7.el7_8
Fixed · RHSA-2020:1230
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.248-1.git.0.92ee8ac.el7
Fixed · RHSA-2020:2992
Red Hat OpenShift Container Platform 4.1
skopeo-1:0.1.32-6.git1715c90.el8_0
Fixed · RHSA-2020:0697
Red Hat OpenShift Container Platform 4.2
openshift-clients-0:4.2.32-202005020632.git.1.1b0fab9.el8
Fixed · RHSA-2020:2027
Red Hat OpenShift Container Platform 4.2
openshift4/ose-docker-builder:v4.2.28-202004061218
Fixed · RHSA-2020:1402
Red Hat OpenShift Container Platform 4.2
openshift4/ose-openshift-controller-manager-rhel7:v4.2.34-202005252115
Fixed · RHSA-2020:3167
Red Hat OpenShift Container Platform 4.2
skopeo-1:0.1.32-7.git1715c90.rhaos4.2.el8
Fixed · RHSA-2020:0689
Red Hat OpenShift Container Platform 4.3
cri-o-0:1.16.4-1.dev.rhaos4.3.git9238eee.el7
Fixed · RHBA-2020:1255
Red Hat OpenShift Container Platform 4.3
openshift-clients-0:4.3.7-202003130552.git.0.6027a27.el7
Fixed · RHSA-2020:0928
Red Hat OpenShift Container Platform 4.3
openshift4/ose-cli-artifacts:v4.3.7-202003161611
Fixed · RHSA-2020:0863
Red Hat OpenShift Container Platform 4.3
openshift4/ose-cli:v4.3.7-202003161611
Fixed · RHSA-2020:0863
Red Hat OpenShift Container Platform 4.3
openshift4/ose-docker-builder:v4.3.7-202003161611
Fixed · RHSA-2020:0863
Red Hat OpenShift Container Platform 4.3
openshift4/ose-openshift-controller-manager-rhel7:v4.3.9-202003230345
Fixed · RHSA-2020:0934
Red Hat OpenShift Container Platform 4.3
podman-0:1.6.4-10.rhaos4.3.el8
Fixed · RHSA-2020:1396
Red Hat OpenShift Container Platform 4.3
skopeo-1:0.1.40-4.rhaos.el8
Fixed · RHSA-2020:0679
Red Hat OpenShift Container Platform 4.4
cri-o-0:1.17.4-8.dev.rhaos4.4.git5f5c5e4.el7
Fixed · RHSA-2020:1937
Red Hat OpenShift Container Platform 4.4
machine-config-daemon-0:4.4.0-202007092124.p0.git.2349.08d34d1.el8
Fixed · RHSA-2020:2927
Red Hat OpenShift Container Platform 4.4
openshift4/ose-cluster-policy-controller-rhel7:v4.4.0-202004261927
Fixed · RHSA-2020:1940
Red Hat OpenShift Container Platform 4.5
machine-config-daemon-0:4.5.0-202007012112.p0.git.2527.d12c3da.el8
Fixed · RHSA-2020:2413
Red Hat Ansible Tower 3
openshift-clients
Not affected
Red Hat Enterprise Linux 8
container-tools:1.0/buildah
Will not fix
Red Hat Enterprise Linux 8
container-tools:1.0/podman
Out of support scope
Red Hat Enterprise Linux 8
container-tools:1.0/skopeo
Out of support scope
Red Hat Enterprise Linux 8
container-tools:2.0/buildah
Will not fix
Red Hat Enterprise Linux 8
container-tools:2.0/podman
Affected
Red Hat Enterprise Linux 8
container-tools:2.0/skopeo
Affected
Red Hat Enterprise Linux 8
container-tools:rhel8/buildah
Will not fix
Red Hat Enterprise Linux 8
container-tools:rhel8/podman
Affected
Red Hat Enterprise Linux 8
container-tools:rhel8/skopeo
Affected
Red Hat OpenShift Container Platform 3.11
cri-o
Will not fix
Red Hat OpenShift Container Platform 3.11
podman
Will not fix
Red Hat OpenShift Container Platform 4
openshift
Will not fix
Red Hat OpenShift Container Platform 4
openshift-enterprise-node-container
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-hyperkube
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-hypershift
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-machine-config-operator
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-tests
Not affected
Red Hat OpenShift Container Platform 4
template-service-broker-container
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extras | buildah-0:1.11.6-8.el7_8 | Fixed | RHSA-2020:1231 |
| Red Hat Enterprise Linux 7 Extras | docker-2:1.13.1-161.git64e9980.el7_8 | Fixed | RHSA-2020:1234 |
| Red Hat Enterprise Linux 7 Extras | podman-0:1.6.4-18.el7_8 | Fixed | RHSA-2020:2117 |
| Red Hat Enterprise Linux 7 Extras | skopeo-1:0.1.40-7.el7_8 | Fixed | RHSA-2020:1230 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.248-1.git.0.92ee8ac.el7 | Fixed | RHSA-2020:2992 |
| Red Hat OpenShift Container Platform 4.1 | skopeo-1:0.1.32-6.git1715c90.el8_0 | Fixed | RHSA-2020:0697 |
| Red Hat OpenShift Container Platform 4.2 | openshift-clients-0:4.2.32-202005020632.git.1.1b0fab9.el8 | Fixed | RHSA-2020:2027 |
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-docker-builder:v4.2.28-202004061218 | Fixed | RHSA-2020:1402 |
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-openshift-controller-manager-rhel7:v4.2.34-202005252115 | Fixed | RHSA-2020:3167 |
| Red Hat OpenShift Container Platform 4.2 | skopeo-1:0.1.32-7.git1715c90.rhaos4.2.el8 | Fixed | RHSA-2020:0689 |
| Red Hat OpenShift Container Platform 4.3 | cri-o-0:1.16.4-1.dev.rhaos4.3.git9238eee.el7 | Fixed | RHBA-2020:1255 |
| Red Hat OpenShift Container Platform 4.3 | openshift-clients-0:4.3.7-202003130552.git.0.6027a27.el7 | Fixed | RHSA-2020:0928 |
| Red Hat OpenShift Container Platform 4.3 | openshift4/ose-cli-artifacts:v4.3.7-202003161611 | Fixed | RHSA-2020:0863 |
| Red Hat OpenShift Container Platform 4.3 | openshift4/ose-cli:v4.3.7-202003161611 | Fixed | RHSA-2020:0863 |
| Red Hat OpenShift Container Platform 4.3 | openshift4/ose-docker-builder:v4.3.7-202003161611 | Fixed | RHSA-2020:0863 |
| Red Hat OpenShift Container Platform 4.3 | openshift4/ose-openshift-controller-manager-rhel7:v4.3.9-202003230345 | Fixed | RHSA-2020:0934 |
| Red Hat OpenShift Container Platform 4.3 | podman-0:1.6.4-10.rhaos4.3.el8 | Fixed | RHSA-2020:1396 |
| Red Hat OpenShift Container Platform 4.3 | skopeo-1:0.1.40-4.rhaos.el8 | Fixed | RHSA-2020:0679 |
| Red Hat OpenShift Container Platform 4.4 | cri-o-0:1.17.4-8.dev.rhaos4.4.git5f5c5e4.el7 | Fixed | RHSA-2020:1937 |
| Red Hat OpenShift Container Platform 4.4 | machine-config-daemon-0:4.4.0-202007092124.p0.git.2349.08d34d1.el8 | Fixed | RHSA-2020:2927 |
| Red Hat OpenShift Container Platform 4.4 | openshift4/ose-cluster-policy-controller-rhel7:v4.4.0-202004261927 | Fixed | RHSA-2020:1940 |
| Red Hat OpenShift Container Platform 4.5 | machine-config-daemon-0:4.5.0-202007012112.p0.git.2527.d12c3da.el8 | Fixed | RHSA-2020:2413 |
| Red Hat Ansible Tower 3 | openshift-clients | Not affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:1.0/buildah | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | container-tools:1.0/podman | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | container-tools:1.0/skopeo | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | container-tools:2.0/buildah | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | container-tools:2.0/podman | Affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:2.0/skopeo | Affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/buildah | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/podman | Affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/skopeo | Affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | cri-o | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | podman | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift-enterprise-node-container | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hyperkube | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hypershift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-machine-config-operator | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-tests | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | template-service-broker-container | Not affected | n/a |
github.com/proglottis/gpgme
Go
Introduced 0 Fixed 0.1.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/proglottis/gpgme | 0 | 0.1.1 |
Remediation
Red Hat statement
OpenShift 3.11 consumes updates for podman from the RHEL-7 extras channel, hence why it has been marked as wontfix in this instance. After extensive testing of the mentioned vulnerability Red Hat has chosen a severity of Moderate instead of High, because the deallocation of GPGME objects while other parts of code are still using it, the vulnerability can only result in a crash and cannot be used to execute code in any feasible manner, moreover the vulnerability only results in crash if finalizers are called to clean up variables while objects are still being used by the underlying C code. Given the inherent attack complexity being high and the exploitability of the vulnerability limited to a crash, Moderate severity seems adequate.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.07% (0.05071) | 92.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.93% (0.04935) | 90.99th | v5 (v2026.06.15) |
| Mar 17, 2026 | 1.94% (0.01939) | 83.25th | v4 (v2025.03.14) |
| Nov 17, 2025 | 2.96% (0.02961) | 85.98th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.01% (0.04013) | 87.38th | v4 (v2025.03.14) |
| Mar 29, 2025 | 13.24% (0.13239) | 90.22th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.01% (0.04013) | 87.69th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.17% (0.01173) | 85.64th | v3 (v2023.03.01) |
| Jan 19, 2024 | 1.17% (0.01173) | 83.48th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.03% (0.01028) | 82.11th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.52% (0.00518) | 73.82th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.42% (0.00417) | 70.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.81% (0.03806) | 85.56th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.81% (0.03806) | 84.08th | v2 (v2022.01.01) |
| Feb 4, 2022 | 25.29% (0.25288) | 95.51th | v2 (v2022.01.01) |
| Feb 3, 2022 | 16.72% (0.16717) | 90.29th | v1 |
| Jan 6, 2022 | 16.72% (0.16717) | 90.17th | v1 |
| Jan 5, 2022 | 4.28% (0.04282) | 83.97th | v5 (v2026.06.15) |
| Apr 14, 2021 | 4.28% (0.04282) | 0.00th | v1 |
References (21)
- https://access.redhat.com/errata/RHSA-2020:0679 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0689 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0697 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-8945 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1795838 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-m6wg-2mwg-4rfq Advisory
- https://github.com/containers/image/commit/4c7a23f82ef09127b0ff28366d1cf31316dd6cc1 x_refsource_MISCPatchThird Party Advisory
- https://github.com/proglottis/gpgme/commit/92153bcb59bd2f511e502262c46c7bd660e21733
- https://github.com/proglottis/gpgme/compare/v0.1.0...v0.1.1 x_refsource_MISCPatchThird Party Advisory
- https://github.com/proglottis/gpgme/pull/23 x_refsource_MISCExploitPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H6P6SSNKN4H6GSEVROHBDXA64PX7EOED/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KDBT77KV3U7BESJX3P4S4MPVDGRTAQA2/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXV7NZELYWRRCXATXU3FYD3G3WJT3WYM/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H6P6SSNKN4H6GSEVROHBDXA64PX7EOED/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KDBT77KV3U7BESJX3P4S4MPVDGRTAQA2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXV7NZELYWRRCXATXU3FYD3G3WJT3WYM/
- https://nvd.nist.gov/vuln/detail/CVE-2020-8945
- https://pkg.go.dev/vuln/GO-2021-0096
- https://www.cve.org/CVERecord?id=CVE-2020-8945
Change history (0)
No recorded changes yet.