UBUNTU-CVE-2022-29526
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
2 explicit affected versions
10 explicit affected versions
8 explicit affected versions
1 explicit affected versions
2 explicit affected versions
5 explicit affected versions
9 explicit affected versions
1 explicit affected versions
1 explicit affected versions
6 explicit affected versions
6 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
05 / REFERENCES
Further evidence
- https://github.com/golang/go/commit/f66925e854e71e0c54b581885380a490d7afa30c
- https://go.dev/issue/52313
- https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU
- https://ubuntu.com/security/CVE-2022-29526
- https://ubuntu.com/security/notices/USN-6038-1
- https://ubuntu.com/security/notices/USN-6038-2
- https://www.cve.org/CVERecord?id=CVE-2022-29526