CVE-2022-29526

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
References
Link Resource
https://github.com/golang/go/issues/52313 Exploit Issue Tracking Patch Third Party Advisory
https://groups.google.com/g/golang-announce Issue Tracking Mailing List Third Party Advisory
https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q6GE5EQGE4L2KRVGW4T75QVIYAXCLO5X/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/
https://security.gentoo.org/glsa/202208-02 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220729-0001/ Third Party Advisory
https://github.com/golang/go/issues/52313 Exploit Issue Tracking Patch Third Party Advisory
https://groups.google.com/g/golang-announce Issue Tracking Mailing List Third Party Advisory
https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q6GE5EQGE4L2KRVGW4T75QVIYAXCLO5X/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/
https://security.gentoo.org/glsa/202208-02 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220729-0001/ Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:netapp:beegfs_csi_driver:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-06-23 17:15

Updated : 2024-11-21 06:59


NVD link : CVE-2022-29526

Mitre link : CVE-2022-29526

CVE.ORG link : CVE-2022-29526


JSON object : View

Products Affected

golang

  • go

linux

  • linux_kernel

netapp

  • beegfs_csi_driver

fedoraproject

  • fedora
CWE
CWE-269

Improper Privilege Management