CVE-2022-29526

Public on 2022-06-23
Modified on 2024-01-12
Description

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Severity
Medium
See what this means
CVSS v3 Base Score
6.2
See breakdown

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 2 - Core go-rpm-macros 2022-10-17 21:46 ALAS2-2022-1863
Amazon Linux 1 golang 2022-09-15 03:57 ALAS-2022-1635
Amazon Linux 2 - Core golang 2022-09-15 04:46 ALAS2-2022-1846
Amazon Linux 2023 golang 2023-02-17 20:45 ALAS2023-2023-048
Amazon Linux 2023 golang-github-cpuguy83-md2man 2023-02-17 20:45 ALAS2023-2023-047
Amazon Linux 2 - Core golang-github-godbus-dbus 2022-10-17 21:46 ALAS2-2022-1858
Amazon Linux 2 - Core golang-github-gorilla-context 2022-10-17 21:46 ALAS2-2022-1859
Amazon Linux 2 - Core golang-github-gorilla-mux 2022-10-17 21:46 ALAS2-2022-1860
Amazon Linux 2 - Core golang-github-kr-pty 2022-10-17 21:46 ALAS2-2022-1864
Amazon Linux 2 - Core golang-github-syndtr-gocapability 2022-10-17 21:46 ALAS2-2022-1865
Amazon Linux 2 - Core golang-googlecode-net 2022-10-17 21:46 ALAS2-2022-1861
Amazon Linux 2 - Core golang-googlecode-sqlite 2022-10-17 21:46 ALAS2-2022-1862
Amazon Linux 2 - Core golist 2022-09-15 04:46 ALAS2-2022-1847
Amazon Linux 2023 golist 2023-02-17 20:45 ALAS2023-2023-046
Amazon Linux 2 - Docker Extra runc 2022-09-30 07:10 ALAS2DOCKER-2022-020

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv2 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N
NVD CVSSv3 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N