CVE-2022-27664
Summary
| CVE | CVE-2022-27664 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-06 18:15:00 UTC |
| Updated | 2023-11-07 03:45:00 UTC |
| Description | In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Application | Golang | Go | All | All | All | All |
| Application | Golang | Go | 1.19.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 37 Update: golang-1.19.1-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [security] Go 1.19.1 and Go 1.18.6 are released | CONFIRM | groups.google.com | |
| [SECURITY] Fedora 36 Update: golang-1.18.6-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: golang-1.19.1-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| golang-announce - Google Groups | MISC | groups.google.com | |
| CVE-2022-27664 Golang Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Go: Multiple Vulnerabilities (GLSA 202209-26) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] Fedora 36 Update: golang-1.18.6-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160173 Oracle Enterprise Linux Security Update for git-lfs (ELSA-2022-7129)
- 160322 Oracle Enterprise Linux Security Update for ol8addon (ELSA-2022-24267)
- 160499 Oracle Enterprise Linux Security Update for ol8addon (ELSA-2023-18908)
- 160582 Oracle Enterprise Linux Security Update for git-lfs (ELSA-2023-2357)
- 160588 Oracle Enterprise Linux Security Update for grafana-pcp security and enhancement update (ELSA-2023-2177)
- 160609 Oracle Enterprise Linux Security Update for image builder (ELSA-2023-2204)
- 160619 Oracle Enterprise Linux Security Update for grafana security and enhancement update (ELSA-2023-2167)
- 160655 Oracle Enterprise Linux Security Update for grafana (ELSA-2023-2784)
- 160665 Oracle Enterprise Linux Security Update for grafana-pcp (ELSA-2023-2785)
- 160666 Oracle Enterprise Linux Security Update for image builder (ELSA-2023-2780)
- 160678 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2023-2758)
- 160696 Oracle Enterprise Linux Security Update for container-tools:4.0 (ELSA-2023-2802)
- 161289 Oracle Enterprise Linux Security Update for container-tools:4.0 (ELSA-2024-0121)
- 183616 Debian Security Update for golang-1.19golang-golang-x-net (CVE-2022-27664)
- 199304 Ubuntu Security Notification for Go Vulnerabilities (USN-6038-1)
- 240773 Red Hat Update for git-lfs (RHSA-2022:7129)
- 240949 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:8626)
- 241070 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2022:7398)
- 241268 Red Hat Update for multiple OpenStack Platforms (RHSA-2023:1275)
- 241423 Red Hat Update for grafana-pcp (RHSA-2023:2177)
- 241424 Red Hat Update for image builder security (RHSA-2023:2204)
- 241440 Red Hat Update for butane security (RHSA-2023:2193)
- 241453 Red Hat Update for grafana (RHSA-2023:2167)
- 241455 Red Hat Update for toolbox (RHSA-2023:2236)
- 241467 Red Hat Update for git-lfs (RHSA-2023:2357)
- 241477 Red Hat Update for grafana-pcp (RHSA-2023:2785)
- 241485 Red Hat Update for grafana (RHSA-2023:2784)
- 241486 Red Hat Update for container-tools:4.0 (RHSA-2023:2802)
- 241490 Red Hat Update for image builder security (RHSA-2023:2780)
- 241505 Red Hat Update for container-tools:rhel8 security (RHSA-2023:2758)
- 241747 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:3613)
- 242374 Red Hat OpenShift Container Platform 4.14 Security Update (RHSA-2023:5009)
- 242882 Red Hat Update for container-tools:4.0 (RHSA-2024:0121)
- 283108 Fedora Security Update for golang (FEDORA-2022-67ec8c61d0)
- 354076 Amazon Linux Security Advisory for golang : ALAS2-2022-1851
- 354080 Amazon Linux Security Advisory for containerd, docker : ALAS2DOCKER-2022-021
- 354088 Amazon Linux Security Advisory for golang-github-syndtr-gocapability : ALAS2-2022-1865
- 354089 Amazon Linux Security Advisory for golang-googlecode-sqlite : ALAS2-2022-1862
- 354090 Amazon Linux Security Advisory for golang-github-kr-pty : ALAS2-2022-1864
- 354091 Amazon Linux Security Advisory for go-rpm-macros : ALAS2-2022-1863
- 354092 Amazon Linux Security Advisory for golang-googlecode-net : ALAS2-2022-1861
- 354093 Amazon Linux Security Advisory for golang-github-gorilla-mux : ALAS2-2022-1860
- 354094 Amazon Linux Security Advisory for golang-github-gorilla-context : ALAS2-2022-1859
- 354096 Amazon Linux Security Advisory for golang-github-godbus-dbus : ALAS2-2022-1858
- 354500 Amazon Linux Security Advisory for golang : ALAS2022-2022-144
- 354527 Amazon Linux Security Advisory for golang : ALAS2022-2022-193
- 354566 Amazon Linux Security Advisory for golang : ALAS-2022-193
- 355212 Amazon Linux Security Advisory for golang : ALAS2023-2023-048
- 356304 Amazon Linux Security Advisory for golang : ALASGOLANG1.19-2023-002
- 356883 Amazon Linux Security Advisory for containerd : ALAS2ECS-2023-022
- 356885 Amazon Linux Security Advisory for containerd : ALAS2NITRO-ENCLAVES-2023-034
- 377746 Alibaba Cloud Linux Security Update for git-lfs (ALINUX3-SA-2022:0180)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378707 Alibaba Cloud Linux Security Update for grafana (ALINUX3-SA-2023:0075)
- 378709 Alibaba Cloud Linux Security Update for grafana-pcp (ALINUX3-SA-2023:0074)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 502503 Alpine Linux Security Update for go
- 502841 Alpine Linux Security Update for docker-cli-compose
- 502858 Alpine Linux Security Update for go
- 672362 EulerOS Security Update for golang (EulerOS-SA-2022-2766)
- 672365 EulerOS Security Update for golang (EulerOS-SA-2022-2731)
- 672441 EulerOS Security Update for golang (EulerOS-SA-2022-2847)
- 672468 EulerOS Security Update for golang (EulerOS-SA-2022-2822)
- 672761 EulerOS Security Update for golang (EulerOS-SA-2023-1505)
- 690935 Free Berkeley Software Distribution (FreeBSD) Security Update for go (6fea7103-2ea4-11ed-b403-3dae8ac60d3e)
- 710627 Gentoo Linux Go Multiple Vulnerabilities (GLSA 202209-26)
- 753111 SUSE Enterprise Linux Security Update for go1.18 (SUSE-SU-2022:3325-1)
- 753397 SUSE Enterprise Linux Security Update for go1.19 (SUSE-SU-2022:3326-1)
- 753994 SUSE Enterprise Linux Security Update for Prometheus Golang clients (SUSE-SU-2023:2187-1)
- 753995 SUSE Enterprise Linux Security Update for SUSE Manager Client Tools (SUSE-SU-2023:2183-1)
- 754047 SUSE Enterprise Linux Security Update for go1.18-openssl (SUSE-SU-2023:2312-1)
- 754116 SUSE Enterprise Linux Security Update for SUSE Manager Client Tools (SUSE-SU-2023:2578-1)
- 770168 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:8626)
- 770172 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2022:7398)
- 770197 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:3613)
- 770213 Red Hat OpenShift Container Platform 4.14 Security Update (RHSA-2023:5009)
- 903763 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10873)
- 903819 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10855)
- 907508 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10855-1)
- 907647 Common Base Linux Mariner (CBL-Mariner) Security Update for kured (31963-1)
- 907767 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10873-1)
- 907808 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10855-2)
- 908043 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10855-5)
- 940722 AlmaLinux Security Update for git-lfs (ALSA-2022:7129)
- 941036 AlmaLinux Security Update for grafana-pcp (ALSA-2023:2177)
- 941038 AlmaLinux Security Update for butane (ALSA-2023:2193)
- 941041 AlmaLinux Security Update for toolbox (ALSA-2023:2236)
- 941046 AlmaLinux Security Update for grafana (ALSA-2023:2167)
- 941053 AlmaLinux Security Update for git-lfs (ALSA-2023:2357)
- 941063 AlmaLinux Security Update for Image (ALSA-2023:2204)
- 941090 AlmaLinux Security Update for container-tools:4.0 (ALSA-2023:2802)
- 941104 AlmaLinux Security Update for grafana (ALSA-2023:2784)
- 941106 AlmaLinux Security Update for grafana-pcp (ALSA-2023:2785)
- 941116 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2023:2758)
- 941118 AlmaLinux Security Update for Image (ALSA-2023:2780)
- 941535 AlmaLinux Security Update for container-tools:4.0 (ALSA-2024:0121)
- 960247 Rocky Linux Security Update for git-lfs (RLSA-2022:7129)