Infinite loop in Go programming language - CVE-2022-30634
Published: March 21, 2023
Vulnerability identifier: #VU73870
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-30634
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in crypto/rand on Windows when handling buffer larger than 1 << 32 - 1 bytes. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
Go programming language
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
Development Tools Module
openSUSE Leap
openEuler
Astronomer with IBM
ObjectScale
Splunk Enterprise
golang
golang-devel
golang-help
go1.17-race
go1.17-doc
go1.17
go1.18-race
go1.18-doc
go1.18
go1.18-openssl
go1.18-openssl-race
go1.18-openssl-doc
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Pak for Multicloud Management Monitoring
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
Cloud Pak for Data
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
Development Tools Module
openSUSE Leap
openEuler
Astronomer with IBM
ObjectScale
Splunk Enterprise
golang
golang-devel
golang-help
go1.17-race
go1.17-doc
go1.17
go1.18-race
go1.18-doc
go1.18
go1.18-openssl
go1.18-openssl-race
go1.18-openssl-doc
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Pak for Multicloud Management Monitoring
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
Cloud Pak for Data
How to mitigate CVE-2022-30634
Install updates from vendor's website.
Go programming language - addressed in versions 1.17.11, 1.18.3
Astronomer with IBM - update to 1.0.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
ObjectScale - update to 1.4.0
golang - update to 1.15.7-14
golang-devel - update to 1.15.7-14
golang-help - update to 1.15.7-14
go1.17-race - update to 1.17.11-150000.1.37.1
go1.17-doc - update to 1.17.11-150000.1.37.1
go1.17 - update to 1.17.11-150000.1.37.1
go1.18-race - update to 1.18.3-150000.1.20.1
go1.18-doc - update to 1.18.3-150000.1.20.1
go1.18 - update to 1.18.3-150000.1.20.1
golang - addressed in versions 1.18.6-1.43, 1.19.8-1
go1.18-openssl - update to 1.18.10.1-150000.1.9.1
go1.18-openssl-race - update to 1.18.10.1-150000.1.9.1
go1.18-openssl-doc - update to 1.18.10.1-150000.1.9.1
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 6
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.3
Cloud Pak for Data - update to 4.8.5
IBM Spectrum Protect Plus - update to 10.1.12
Astronomer with IBM - update to 1.0.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
ObjectScale - update to 1.4.0
golang - update to 1.15.7-14
golang-devel - update to 1.15.7-14
golang-help - update to 1.15.7-14
go1.17-race - update to 1.17.11-150000.1.37.1
go1.17-doc - update to 1.17.11-150000.1.37.1
go1.17 - update to 1.17.11-150000.1.37.1
go1.18-race - update to 1.18.3-150000.1.20.1
go1.18-doc - update to 1.18.3-150000.1.20.1
go1.18 - update to 1.18.3-150000.1.20.1
golang - addressed in versions 1.18.6-1.43, 1.19.8-1
go1.18-openssl - update to 1.18.10.1-150000.1.9.1
go1.18-openssl-race - update to 1.18.10.1-150000.1.9.1
go1.18-openssl-doc - update to 1.18.10.1-150000.1.9.1
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 6
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.3
Cloud Pak for Data - update to 4.8.5
IBM Spectrum Protect Plus - update to 10.1.12
External References
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- Multiple vulnerabilities in Oracle Solaris
- Amazon Linux AMI update for golang
- SUSE update for go1.18-openssl
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Security Services
- openEuler update for golang
- Amazon Linux AMI update for golang
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Cloud Pak for Data
- SUSE update for go1.17
- SUSE update for go1.18
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Astronomer with IBM