Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-34156

Опубликовано: 06 сент. 2024
Источник: debian
EPSS Низкий

Описание

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.23fixed1.23.1-1package
golang-1.22fixed1.22.7-1package
golang-1.21unfixedpackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc

  • https://go.dev/issue/69139

  • https://github.com/golang/go/commit/fa8ff1a46deb6c816304441ec6740ec112e19012 (go1.23.1)

  • https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01 (go1.22.7)

EPSS

Процентиль: 31%
0.00114
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
redhat
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
nvd
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

rocky
8 месяцев назад

Important: skopeo security update

rocky
8 месяцев назад

Important: containernetworking-plugins security update

EPSS

Процентиль: 31%
0.00114
Низкий