CVE-2022-27536: High severity golang vulnerability
Published Apr 20, 2022
·Updated
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
Affected Software
2 affected components
Golang>=1.18.0<1.18.1
macOS
Event History
Apr 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-27536.
2
What is the severity of CVE-2022-27536?
CVE-2022-27536 has a severity level of 7.5 (High).
3
What is the affected software for CVE-2022-27536?
The affected software for CVE-2022-27536 is Go 1.18.x before 1.18.1 on macOS.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote TLS server to cause a TLS client to panic.
5
Are there any fixes or patches available for CVE-2022-27536?
Yes, the fix for CVE-2022-27536 is available in Go 1.18.1.