Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Golang
Subscribe
|
Go
Subscribe
|
|
Redhat
Subscribe
|
Acm
Subscribe
Ceph Storage
Subscribe
Container Native Virtualization
Subscribe
Devtools
Subscribe
Enterprise Linux
Subscribe
Multicluster Engine
Subscribe
Openshift Api Data Protection
Subscribe
Openshift Custom Metrics Autoscaler
Subscribe
Openshift Data Foundation
Subscribe
Openshift Secondary Scheduler
Subscribe
Openstack
Subscribe
Rhmt
Subscribe
Serverless
Subscribe
Service Mesh
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52466 | Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures. |
Ubuntu USN |
USN-6038-1 | Go vulnerabilities |
Ubuntu USN |
USN-6038-2 | Go vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
Redhat multicluster Engine |
|
| CPEs | cpe:/a:redhat:acm:2.5::el8 cpe:/a:redhat:acm:2.6::el8 cpe:/a:redhat:multicluster_engine:2.1::el8 |
|
| Vendors & Products |
Redhat acm
Redhat multicluster Engine |
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.6::el8 cpe:/a:redhat:multicluster_engine:2.1::el8 |
|
| Vendors & Products |
Redhat acm
Redhat multicluster Engine |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2024-08-03T06:56:13.235Z
Reserved: 2022-05-12T00:00:00
Link: CVE-2022-30635
No data.
Status : Modified
Published: 2022-08-10T20:15:42.640
Modified: 2024-11-21T07:03:04.467
Link: CVE-2022-30635
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN