FlawAtlas
Search the atlas
CVE-2022-29526 Moderate

CVE-2022-29526

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Exploit probability 2.6%
Published June 22, 2022
Required by Not available
Last source change August 12, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

147 explicit affected versions

Go golang.org/x/sys
Go golang.org/x/sys
Go stdlib
Bitnami golang

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2022-29526

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

View original source
Open Source Vulnerabilities GHSA-p782-xgp4-8hr8

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Reporting in syscall. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible. ### Specific Go Packages Affected golang.org/x/sys/unix

View original source
Open Source Vulnerabilities GO-2022-0493

When called with a non-zero flags parameter, the Faccessat function can incorrectly report that a file is accessible.

View original source
Open Source Vulnerabilities BIT-golang-2022-29526

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

View original source

05 / REFERENCES

Further evidence