CVE-2022-32189
Summary
| CVE | CVE-2022-32189 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-10 20:15:00 UTC |
| Updated | 2023-03-03 15:39:00 UTC |
| Description | A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Application | Golang | Go | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GO-2022-0537 - Go Packages | MISC | pkg.go.dev | |
| go.dev/cl/417774 | MISC | go.dev | |
| 055113ef364337607e3e72ed7d48df67fde6fc66 - go - Git at Google | MISC | go.googlesource.com | |
| [security] Go 1.18.5 and Go 1.17.13 are released | MISC | groups.google.com | |
| [SECURITY] Fedora 36 Update: golang-1.18.5-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE-2022-32189 Golang Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| math/big: index out of range in Float.GobDecode · Issue #53871 · golang/go · GitHub | MISC | go.dev | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160077 Oracle Enterprise Linux Security Update for golang (ELSA-2022-20694)
- 160078 Oracle Enterprise Linux Security Update for golang (ELSA-2022-20693)
- 160173 Oracle Enterprise Linux Security Update for git-lfs (ELSA-2022-7129)
- 160202 Oracle Enterprise Linux Security Update for ol8addon (ELSA-2022-23681)
- 160218 Oracle Enterprise Linux Security Update for image builder (ELSA-2022-7548)
- 160295 Oracle Enterprise Linux Security Update for image builder (ELSA-2022-7950)
- 160322 Oracle Enterprise Linux Security Update for ol8addon (ELSA-2022-24267)
- 160582 Oracle Enterprise Linux Security Update for git-lfs (ELSA-2023-2357)
- 160678 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2023-2758)
- 160696 Oracle Enterprise Linux Security Update for container-tools:4.0 (ELSA-2023-2802)
- 181907 Debian Security Update for golang-1.19 (CVE-2022-32189)
- 199304 Ubuntu Security Notification for Go Vulnerabilities (USN-6038-1)
- 240773 Red Hat Update for git-lfs (RHSA-2022:7129)
- 240856 Red Hat Update for image builder security (RHSA-2022:7548)
- 240896 Red Hat Update for image builder security (RHSA-2022:7950)
- 240939 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:8534)
- 240949 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:8626)
- 241070 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2022:7398)
- 241268 Red Hat Update for multiple OpenStack Platforms (RHSA-2023:1275)
- 241440 Red Hat Update for butane security (RHSA-2023:2193)
- 241455 Red Hat Update for toolbox (RHSA-2023:2236)
- 241467 Red Hat Update for git-lfs (RHSA-2023:2357)
- 241486 Red Hat Update for container-tools:4.0 (RHSA-2023:2802)
- 241505 Red Hat Update for container-tools:rhel8 security (RHSA-2023:2758)
- 283031 Fedora Security Update for golang (FEDORA-2022-1f829990f0)
- 354527 Amazon Linux Security Advisory for golang : ALAS2022-2022-193
- 354566 Amazon Linux Security Advisory for golang : ALAS-2022-193
- 354901 Amazon Linux Security Advisory for golang : ALAS-2023-1731
- 355212 Amazon Linux Security Advisory for golang : ALAS2023-2023-048
- 377746 Alibaba Cloud Linux Security Update for git-lfs (ALINUX3-SA-2022:0180)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 502469 Alpine Linux Security Update for go
- 672294 EulerOS Security Update for golang (EulerOS-SA-2022-2651)
- 672302 EulerOS Security Update for golang (EulerOS-SA-2022-2683)
- 672320 EulerOS Security Update for golang (EulerOS-SA-2022-2710)
- 672362 EulerOS Security Update for golang (EulerOS-SA-2022-2766)
- 672365 EulerOS Security Update for golang (EulerOS-SA-2022-2731)
- 672413 EulerOS Security Update for golang (EulerOS-SA-2022-2795)
- 690906 Free Berkeley Software Distribution (FreeBSD) Security Update for go (7f8d5435-125a-11ed-9a69-10c37b4ac2ea)
- 710584 Gentoo Linux Go Multiple Vulnerabilities (GLSA 202208-02)
- 752444 SUSE Enterprise Linux Security Update for go1.17 (SUSE-SU-2022:2671-1)
- 753134 SUSE Enterprise Linux Security Update for go1.18 (SUSE-SU-2022:2672-1)
- 754047 SUSE Enterprise Linux Security Update for go1.18-openssl (SUSE-SU-2023:2312-1)
- 770167 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:8534)
- 770168 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:8626)
- 770172 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2022:7398)
- 902712 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10521)
- 902731 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10539)
- 903924 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10539-1)
- 904017 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10521-1)
- 907768 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10521-2)
- 907862 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10539-2)
- 940722 AlmaLinux Security Update for git-lfs (ALSA-2022:7129)
- 940769 AlmaLinux Security Update for Image (ALSA-2022:7548)
- 940831 AlmaLinux Security Update for Image (ALSA-2022:7950)
- 941038 AlmaLinux Security Update for butane (ALSA-2023:2193)
- 941041 AlmaLinux Security Update for toolbox (ALSA-2023:2236)
- 941053 AlmaLinux Security Update for git-lfs (ALSA-2023:2357)
- 941090 AlmaLinux Security Update for container-tools:4.0 (ALSA-2023:2802)
- 941116 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2023:2758)
- 960247 Rocky Linux Security Update for git-lfs (RLSA-2022:7129)
- 960529 Rocky Linux Security Update for Image (RLSA-2022:7548)
- 960560 Rocky Linux Security Update for Image (RLSA-2022:7950)