CVE-2022-2879

Aliases:GO-2022-1037BIT-golang-2022-2879DEBIAN-CVE-2022-2879CGA-3228-f4r3-f32mCGA-38cv-v4x4-pf26CGA-6q32-7jm9-8vrqCGA-6rh5-63qc-82c8CGA-6wfm-pxj4-m2jhCGA-98h6-5vg6-7m23CGA-9qmw-pxff-4246CGA-fw68-x73p-42gqCGA-fwg6-4w6r-rj2vCGA-gph4-74wc-x887CGA-gqfh-7rg5-7hp3CGA-hh6g-5g42-79f4CGA-m39q-83h4-q7pcCGA-m45c-9rpr-wcwgCGA-p44c-mcph-86mcCGA-pj2p-xvq8-7m5vCGA-r6f2-6822-23rvCGA-v494-jmfm-mxp2CGA-867g-rwrm-78q2CGA-cg75-7369-5w8r
Modified
Published: 14 Oct 2022, 00:00
Last modified:13 Feb 2025, 16:32

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
1.67% LOW
2% probability +1.65%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Oct 2022, 00:00
Published
Vulnerability first disclosed
13 Feb 2025, 16:32
Last Modified
Vulnerability information updated

Description

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 1.67% Percentile: 76%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    all

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • wolfikatib-earlystopping

    < 0.19.0-r31

  • wolfikatib-suggestion-goptuna-compat

    all

  • wolfikatib-suggestion-hyperband

    < 0.19.0-r31

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • wolfikatib-suggestion-nas-darts

    < 0.19.0-r31

  • wolfikatib-suggestion-nas-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-optuna-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-pbt-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-skopt-enas

    < 0.19.0-r31

  • wolfikatib-tfevent-metricscollector

    < 0.19.0-r31

  • debiangolang-1.15

    all

  • debiangolang-1.19

    < 1.19.2-1

  • go standard libraryarchive/tar

    < 1.18.7 | ≥ 1.19.0-0, < 1.19.2

  • golanggo

    < 1.18.7 | ≥ 1.19.0, < 1.19.2

  • Gostdlib

    ≥ 1.19.0-0, < 1.19.2

References (6)