Input validation error in Go programming language - CVE-2022-41716
Published: November 17, 2022
Vulnerability details
The vulnerability allows a local user to execute arbitrary OS commands on the system.
The vulnerability exists due to insecure processing of unsanitized NUL values in syscall.StartProcess and os/exec.Cmd. A local user on the Windows operating system can set a specially crafted environment variable and execute arbitrary OS commands on the system.
Affected software
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
Development Tools Module
openSUSE Leap
openEuler
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Astronomer with IBM
containerd
Db2 Rest
ObjectScale
Dell EMC Streaming Data Platform
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Dell PowerProtect Cyber Recovery
Robotic Process Automation for Cloud Pak
AdGuard Home
Dell Data Lakehouse
QRadar Suite
Splunk Enterprise
IBM Cloud Pak System
IBM Watson Assistant for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Spectrum Copy Data Management
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes
IBM Spectrum Protect Plus
IBM Cloud Pak for Business Automation
golist
golang-help
golang-devel
golang
go1.18-race
go1.18-doc
go1.18
go1.18-openssl-doc
go1.18-openssl
go1.18-openssl-race
go1.19
go1.19-doc
go1.19-race
watsonx.data
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2022-41716
AdGuard Home - addressed in versions 0.107.17, 0.108.0-b.20
Astronomer with IBM - update to 1.0.1
containerd - update to 1.6.10
QRadar Suite - update to 1.10.18.0
IBM Cloud Pak System - update to 2.3.3.6
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
golist - update to 0.10.1-11
Db2 Rest - addressed in versions 1.0.0.240, 1.0.0.246
ObjectScale - update to 1.4.0
Dell Data Lakehouse - update to 1.4.0.0
Netcool Operations Insight - update to 1.6.9
Dell EMC Streaming Data Platform - update to 1.7.0
golang-help - update to 1.15.7-22
golang-devel - update to 1.15.7-22
golang - update to 1.15.7-22
go1.18-race - update to 1.18.8-150000.1.37.1
go1.18-doc - update to 1.18.8-150000.1.37.1
go1.18 - update to 1.18.8-150000.1.37.1
go1.18-openssl-doc - update to 1.18.10.1-150000.1.9.1
go1.18-openssl - update to 1.18.10.1-150000.1.9.1
go1.18-openssl-race - update to 1.18.10.1-150000.1.9.1
golang - update to 1.19.3-2
go1.19 - update to 1.19.3-150000.1.15.1
go1.19-doc - update to 1.19.3-150000.1.15.1
go1.19-race - update to 1.19.3-150000.1.15.1
watsonx.data - update to 2.0.1
IBM Spectrum Copy Data Management - update to 2.2.18.1
Cloud Pak for Network Automation - update to 2.4.7
IBM Cloud Pak for Watson AIOps - update to 3.6.2
IBM Decision Optimization for Cloud Pak for Data - update to 4.6.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
IBM Spectrum Protect Plus Container Backup and Restore for OpenShift - update to 10.1.12.4
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes - update to 10.1.12.4
IBM Spectrum Protect Plus - update to 10.1.15
IBM CICS TX Standard - update to 11.1.0.0 ifix7
IBM CICS TX Advanced - update to 11.1.0.0 ifix7
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.18, 22.0.2.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.4
External References
Related Security Bulletins
- Privilege escalation in Go programming language
- Containerd update for Go
- SUSE update for go1.19
- SUSE update for go1.18
- AdGuardHome update for Go
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Multiple vulnerabilities in IBM Decision Optimization in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in IBM Cloud Pak System
- Input validation error in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Db2 REST
- SUSE update for go1.18-openssl
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell Streaming Data Platform
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Oracle Solaris third-party software
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Spectrum Protect Plus Container backup and restore for Kubernetes and OpenShift
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM QRadar Suite Software
- openEuler update for golang
- Amazon Linux AMI update for golist
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM watsonx.data
- Dell Data Lakehouse update for third-party components
- Multiple vulnerabilities in IBM Astronomer with IBM