CVE-2022-27664: High severity Golang Go vulnerability
A closing HTTP/2 server connection could hang forever waiting for a clean shutdown that was preempted by a subsequent fatal error. This failure mode could be exploited to cause a denial of service.
References: https://go.dev/issue/54658 https://groups.google.com/g/golang-announce/c/x49AQzIVX-s/m/0tgO0pjiBQAJ
Upstream Commits: Master: https://github.com/golang/go/commit/29af494fca8a25d7d46276f6d4835c4dcd09e47d Branch.go1.18 : https://github.com/golang/go/commit/5bc9106458fc07851ac324a4157132a91b1f3479 Branch.go1.19 : https://github.com/golang/go/commit/9cfe4e258b1c9d4a04a42539c21c7bdb2e227824
Other sources
A flaw was found in the golang package. In net/http in Go, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if a fatal error preempts the shutdown.
Golang Go is vulnerable to a denial of service, caused by a flaw in net/http. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a closing HTTP/2 server connection to hang, and results in a denial of service condition.
— IBM
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1 attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
— Microsoft
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/openshift-serverless-clientsto a version that resolves this vulnerability.Fixed in 0:1.6.1-1.el8 - Upgrade
Upgrade
redhat/git-lfsto a version that resolves this vulnerability.Fixed in 0:2.13.3-3.el8_6 - Upgrade
Upgrade
redhat/osbuild-composerto a version that resolves this vulnerability.Fixed in 0:75-1.el8 - Upgrade
Upgrade
redhat/weldr-clientto a version that resolves this vulnerability.Fixed in 0:35.9-2.el8 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 0:7.5.15-4.el8 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 0:3.2.0-3.el8 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 0:1.18.9-1.el9_1 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 0:9.0.9-2.el9 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 0:5.1.1-1.el9 - Upgrade
Upgrade
redhat/butaneto a version that resolves this vulnerability.Fixed in 0:0.16.0-1.el9 - Upgrade
Upgrade
redhat/osbuild-composerto a version that resolves this vulnerability.Fixed in 0:76-2.el9_2 - Upgrade
Upgrade
redhat/weldr-clientto a version that resolves this vulnerability.Fixed in 0:35.9-1.el9 - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0:0.0.99.3-9.el9 - Upgrade
Upgrade
redhat/git-lfsto a version that resolves this vulnerability.Fixed in 0:3.2.0-1.el9 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.24.4-5.rhaos4.11.git57d7127.el8 - Upgrade
Upgrade
redhat/cri-toolsto a version that resolves this vulnerability.Fixed in 0:1.24.2-7.el8 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.25.1-5.rhaos4.12.git6005903.el8 - Upgrade
Upgrade
redhat/cri-toolsto a version that resolves this vulnerability.Fixed in 0:1.25.0-2.el8 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.12.0-202301042257.p0.g854f807.assembly.stream.el8 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 3:4.2.0-7.rhaos4.12.el9 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 2:1.9.4-3.rhaos4.12.el9 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.12.0-202308151125.p0.gf61957e.assembly.stream.el9 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.13.0-202308112024.p0.g17b7acc.assembly.stream.el9 - Upgrade
Upgrade
redhat/etcdto a version that resolves this vulnerability.Fixed in 0:3.3.23-12.el8 - Upgrade
Upgrade
redhat/kubevirtto a version that resolves this vulnerability.Fixed in 0:4.13.0-1469.el7 - Upgrade
Upgrade
redhat/kubevirtto a version that resolves this vulnerability.Fixed in 0:4.13.0-1469.el8 - Upgrade
Upgrade
redhat/kubevirtto a version that resolves this vulnerability.Fixed in 0:4.13.0-1469.el9 - Upgrade
Upgrade
go/golang.org/x/net/http2to a version that resolves this vulnerability.Fixed in 0.0.0-20220906165146-f3363e06e74c - Upgrade
Upgrade
go/golang.org/x/netto a version that resolves this vulnerability.Fixed in 0.0.0-20220906165146-f3363e06e74c - Upgrade
Upgrade
debian/golang-1.19to a version that resolves this vulnerability.Fixed in 1.19.8-2 - Upgrade
Upgrade
debian/golang-golang-x-netto a version that resolves this vulnerability.Fixed in 1:0.7.0+dfsg-1Fixed in 1:0.27.0-1 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.19.1 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.18.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.18.8-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.13.2-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.21.6-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.17.13-2 - Upgrade
Upgrade
golang/net/httpto a version that resolves this vulnerability.Fixed in 1.18.6 - Upgrade
Upgrade
golang/net/httpto a version that resolves this vulnerability.Fixed in 1.19.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:8634
- RHSA-2023:1042
- RHSA-2023:0708
- RHSA-2023:0584
- RHSA-2023:0631
- RHSA-2023:3642
- RHSA-2022:7129
- RHSA-2023:0446
- RHSA-2023:2758
- RHSA-2023:2780
- RHSA-2023:2784
- RHSA-2023:2785
- RHSA-2023:2802
- RHSA-2023:0328
- RHSA-2023:2167
- RHSA-2023:2177
- RHSA-2023:2193
- RHSA-2023:2204
- RHSA-2023:2236
- RHSA-2023:2357
- RHSA-2023:0693
- RHBA-2023:0564
- RHSA-2022:8535
- RHSA-2022:8626
- RHSA-2022:7398
- RHSA-2023:3613
- RHSA-2023:4674
- RHSA-2023:4734
- RHSA-2023:0542
- RHSA-2023:1275
- RHSA-2023:3204
- RHSA-2023:3205
- RHSA-2023:3742
- RHSA-2022:8781
- RHSA-2023:0264
- RHSA-2023:0709
- RHSA-2023:1529
- IBM-7183851
Frequently Asked Questions
What is CVE-2022-27664?
CVE-2022-27664 is a vulnerability in the golang package that allows a denial of service attack by causing a closing HTTP/2 server connection to hang.
How does CVE-2022-27664 affect Golang Go?
CVE-2022-27664 affects Golang Go by enabling a remote attacker to exploit the vulnerability and cause a denial of service condition.
What is the severity level of CVE-2022-27664?
CVE-2022-27664 has a severity level of high.
How can I fix CVE-2022-27664?
To fix CVE-2022-27664, you need to update the affected software to version 0.0.0-20220906165146-f3363e06e74c or later.
Where can I find more information about CVE-2022-27664?
You can find more information about CVE-2022-27664 on the NIST website and the Golang announcement groups.