FlawAtlas
Search the atlas
UBUNTU-CVE-2022-30635 High

UBUNTU-CVE-2022-30635

Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.

Exploit probability Not scored
Published August 10, 2022
Required by Not available
Last source change March 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS golang-1.18

1 explicit affected versions

Ubuntu:20.04:LTS golang-1.13

9 explicit affected versions

Ubuntu:20.04:LTS golang-1.16

1 explicit affected versions

Ubuntu:20.04:LTS golang-1.18

1 explicit affected versions

Ubuntu:22.04:LTS golang-1.13

2 explicit affected versions

Ubuntu:22.04:LTS golang-1.18

6 explicit affected versions

Ubuntu:Pro:16.04:LTS golang-1.13

3 explicit affected versions

Ubuntu:Pro:18.04:LTS golang-1.13

3 explicit affected versions

Ubuntu:Pro:18.04:LTS golang-1.16

1 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2022-30635

Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.

View original source

05 / REFERENCES

Further evidence