High severity7.5NVD Advisory· Published Feb 12, 2020· Updated Jun 17, 2026
CVE-2020-8945
CVE-2020-8945
Description
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/proglottis/gpgmeGo | < 0.1.1 | 0.1.1 |
Affected products
20cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.4:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.2:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- proglottis/GPGME librarydescription
Patches
Vulnerability mechanics
References
19- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/containers/image/commit/4c7a23f82ef09127b0ff28366d1cf31316dd6cc1nvdPatchThird Party AdvisoryWEB
- github.com/proglottis/gpgme/compare/v0.1.0...v0.1.1nvdPatchThird Party AdvisoryWEB
- github.com/proglottis/gpgme/pull/23nvdExploitPatchThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0679nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0689nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0697nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-m6wg-2mwg-4rfqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-8945ghsaADVISORY
- github.com/proglottis/gpgme/commit/92153bcb59bd2f511e502262c46c7bd660e21733ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LXghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/H6P6SSNKN4H6GSEVROHBDXA64PX7EOEDghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/KDBT77KV3U7BESJX3P4S4MPVDGRTAQA2ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/WXV7NZELYWRRCXATXU3FYD3G3WJT3WYMghsaWEB
- pkg.go.dev/vuln/GO-2021-0096ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H6P6SSNKN4H6GSEVROHBDXA64PX7EOED/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KDBT77KV3U7BESJX3P4S4MPVDGRTAQA2/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXV7NZELYWRRCXATXU3FYD3G3WJT3WYM/nvd
News mentions
0No linked articles in our index yet.