CVE-2022-27664

Name
CVE-2022-27664
Description
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://groups.google.com/g/golang-announce/c/x49AQzIVX-s
MISC https://groups.google.com/g/golang-announce
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/
Third Party Advisory https://security.netapp.com/advisory/ntap-20220923-0004/
Third Party Advisory https://security.gentoo.org/glsa/202209-26
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:golang:go:1.19.0:*:*:*:*:*:*:* go == None == 1.19.0
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* go >= None < 1.18.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
go edge-community 1.19.1-r0 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
go edge-community 1.18.5-r0 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
go edge-community 1.18.4-r0 None possibly vulnerable
go edge-community 1.18.1-r0 None possibly vulnerable
go edge-community 1.17.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.17.7-r0 None possibly vulnerable
go edge-community 1.17.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.17.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.17.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.17.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.17-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.16.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.16.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.16.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.16.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
go edge-community 1.16.2-r0 None possibly vulnerable
go edge-community 1.15.7-r0 None possibly vulnerable
go edge-community 1.15.5-r0 None possibly vulnerable
go edge-community 1.15.2-r0 None possibly vulnerable
go edge-community 1.15-r0 None possibly vulnerable
go edge-community 1.14.5-r0 None possibly vulnerable
go edge-community 1.13.7-r0 None possibly vulnerable
go edge-community 1.13.2-r0 None possibly vulnerable
go edge-community 1.13.1-r0 None possibly vulnerable
go edge-community 1.12.8-r0 None possibly vulnerable
go edge-community 1.11.5-r0 None possibly vulnerable
go edge-community 1.9.4-r0 None possibly vulnerable
go 3.22-community 1.19.1-r0 None fixed
go 3.22-community 1.18.5-r0 None possibly vulnerable
go 3.22-community 1.18.4-r0 None possibly vulnerable
go 3.22-community 1.18.1-r0 None possibly vulnerable
go 3.22-community 1.17.8-r0 None possibly vulnerable
go 3.22-community 1.17.7-r0 None possibly vulnerable
go 3.22-community 1.17.6-r0 None possibly vulnerable
go 3.22-community 1.17.3-r0 None possibly vulnerable
go 3.22-community 1.17.2-r0 None possibly vulnerable
go 3.22-community 1.17.1-r0 None possibly vulnerable
go 3.22-community 1.17-r0 None possibly vulnerable
go 3.22-community 1.16.7-r0 None possibly vulnerable
go 3.22-community 1.16.6-r0 None possibly vulnerable
go 3.22-community 1.16.5-r0 None possibly vulnerable
go 3.22-community 1.16.4-r0 None possibly vulnerable
go 3.22-community 1.16.2-r0 None possibly vulnerable
go 3.22-community 1.15.7-r0 None possibly vulnerable
go 3.22-community 1.15.5-r0 None possibly vulnerable
go 3.22-community 1.15.2-r0 None possibly vulnerable
go 3.22-community 1.15-r0 None possibly vulnerable
go 3.22-community 1.14.5-r0 None possibly vulnerable
go 3.22-community 1.13.7-r0 None possibly vulnerable
go 3.22-community 1.13.2-r0 None possibly vulnerable
go 3.22-community 1.13.1-r0 None possibly vulnerable
go 3.22-community 1.12.8-r0 None possibly vulnerable
go 3.22-community 1.11.5-r0 None possibly vulnerable
go 3.22-community 1.9.4-r0 None possibly vulnerable
go 3.21-community 1.19.1-r0 None fixed
go 3.20-community 1.19.1-r0 None fixed
go 3.19-community 1.19.1-r0 None fixed
go 3.18-community 1.19.1-r0 None fixed
go 3.17-community 1.19.1-r0 None fixed
docker-cli-compose edge-community 2.15.1-r0 Jake Buchholz Göktürk <tomalok@gmail.com> fixed
docker-cli-compose 3.22-community 2.15.1-r0 None fixed
docker-cli-compose 3.21-community 2.15.1-r0 None fixed
docker-cli-compose 3.20-community 2.15.1-r0 None fixed
docker-cli-compose 3.19-community 2.15.1-r0 None fixed
docker-cli-compose 3.18-community 2.15.1-r0 None fixed
docker-cli-compose 3.17-community 2.15.1-r0 Jake Buchholz Göktürk <tomalok@gmail.com> fixed