Candidate: CVE-2022-24921 PublicDate: 2022-03-05 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921 https://github.com/golang/go/issues/51112 https://groups.google.com/g/golang-announce/c/RP1hfrBYVuk https://github.com/golang/go/commit/ac071634c487eb6ac5422652de3c7c18fba7c522 (go1.17.8) Description: regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_golang-1.6: upstream_golang-1.6: needs-triage esm-infra/xenial_golang-1.6: needs-triage trusty_golang-1.6: ignored (out of standard support) xenial_golang-1.6: ignored (out of standard support) Patches_golang-1.8: upstream_golang-1.8: needs-triage trusty_golang-1.8: ignored (out of standard support) xenial_golang-1.8: ignored (out of standard support) bionic_golang-1.8: needs-triage Patches_golang-1.9: upstream_golang-1.9: needs-triage trusty_golang-1.9: ignored (out of standard support) xenial_golang-1.9: ignored (out of standard support) bionic_golang-1.9: needs-triage Patches_golang-1.10: upstream_golang-1.10: needs-triage trusty/esm_golang-1.10: needs-triage esm-infra/xenial_golang-1.10: needs-triage trusty_golang-1.10: ignored (out of standard support) xenial_golang-1.10: ignored (out of standard support) bionic_golang-1.10: needs-triage Patches_golang-1.13: upstream_golang-1.13: needs-triage trusty_golang-1.13: ignored (out of standard support) xenial_golang-1.13: ignored (out of standard support) bionic_golang-1.13: needs-triage focal_golang-1.13: needs-triage impish_golang-1.13: needs-triage jammy_golang-1.13: needs-triage devel_golang-1.13: needs-triage Patches_golang-1.14: upstream_golang-1.14: needs-triage trusty_golang-1.14: ignored (out of standard support) xenial_golang-1.14: ignored (out of standard support) focal_golang-1.14: needs-triage Patches_golang-1.15: upstream_golang-1.15: needs-triage trusty_golang-1.15: ignored (out of standard support) xenial_golang-1.15: ignored (out of standard support) impish_golang-1.15: needs-triage Patches_golang-1.16: upstream_golang-1.16: needs-triage trusty_golang-1.16: ignored (out of standard support) xenial_golang-1.16: ignored (out of standard support) focal_golang-1.16: needs-triage impish_golang-1.16: needs-triage jammy_golang-1.16: DNE devel_golang-1.16: DNE Patches_golang-1.17: upstream_golang-1.17: released (1.17.8-1) trusty_golang-1.17: ignored (out of standard support) xenial_golang-1.17: ignored (out of standard support) impish_golang-1.17: needs-triage jammy_golang-1.17: needs-triage devel_golang-1.17: needs-triage