CVE-2022-24921
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
02 / AFFECTED SOFTWARE
Affected packages
155 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
On 64-bit platforms, an extremely deeply nested expression can cause regexp.Compile to cause goroutine stack exhaustion, forcing the program to exit. Note this applies to very large expressions, on the order of 2MB.
05 / REFERENCES
Further evidence
- https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24921.json
- https://groups.google.com/g/golang-announce/c/RP1hfrBYVuk
- https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html
- https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html
- https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html
- https://nvd.nist.gov/vuln/detail/CVE-2022-24921
- https://security.gentoo.org/glsa/202208-02
- https://security.netapp.com/advisory/ntap-20220325-0010/
- https://go.dev/cl/384616
- https://go.dev/issue/51112
- https://go.googlesource.com/go/+/452f24ae94f38afa3704d4361d91d51218405c0a