Vulnerability CVE-2022-24921: Information

Description

regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: March 5, 2022
Modified: Aug. 8, 2023
Error type identifier: CWE-674

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
golangsisyphus1.17.8-alt11.22.2-alt1ALT-PU-2022-1429-1296255Fixed
golangsisyphus_riscv641.17.8-alt11.22.2-alt1ALT-PU-2022-4216-1-Fixed
golangp101.16.15-alt11.21.9-alt1ALT-PU-2022-1437-1296256Fixed
golangp91.19.12-alt11.15.15-alt1ALT-PU-2023-5153-1326713Testing
golangc10f11.16.15-alt11.21.9-alt1ALT-PU-2022-1437-1296256Fixed
golangc9f21.16.15-alt1.c91.20.11-alt1ALT-PU-2022-1435-1296257Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
      End excliding
      1.16.15

      cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
      Start including
      1.17
      End excliding
      1.17.8

      Configuration 2

      cpe:2.3:a:netapp:astra_trident:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*