CVE-2022-30630: Stack exhaustion in Glob on certain paths in io/fs
A flaw was found in the golang standard library, io/fs. Calling Glob on a path that contains a large number of path separators can cause a panic issue due to stack exhaustion. This could allow an attacker to impact availability.
Other sources
Calling Glob on a path which contains a large number of path separators can cause a panic due to stack exhaustion.
— Red Hat
Golang Go is vulnerable to a denial of service, caused by an uncontrolled recursion flaw in Glob in io/fs due to stack exhaustion. By sending a specially-crafted request using a path which contains a large number of path separators, a remote attacker could exploit this vulnerability to cause a panic.
— IBM
Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/skupper-clito a version that resolves this vulnerability.Fixed in 0:1.0.2-2.el8 - Upgrade
Upgrade
redhat/openshift-serverless-clientsto a version that resolves this vulnerability.Fixed in 0:1.3.1-4.el8 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.17-golang-0:1.17.12-1.el7_9 - Upgrade
Upgrade
redhat/git-lfsto a version that resolves this vulnerability.Fixed in 0:2.13.3-3.el8_6 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 0:7.5.15-3.el8 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 0:3.2.0-2.el8 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 0:1.17.12-1.el9_0 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 0:7.5.15-3.el9 - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0:0.0.99.3-5.el9 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 0:3.2.0-3.el9 - Upgrade
Upgrade
redhat/git-lfsto a version that resolves this vulnerability.Fixed in 0:3.2.0-1.el9 - Upgrade
Upgrade
redhat/etcdto a version that resolves this vulnerability.Fixed in 0:3.3.23-12.el8 - Upgrade
Upgrade
redhat/kubevirtto a version that resolves this vulnerability.Fixed in 0:4.12.0-1057.el7 - Upgrade
Upgrade
redhat/kubevirtto a version that resolves this vulnerability.Fixed in 0:4.12.0-1057.el8 - Upgrade
Upgrade
debian/golang-1.15to a version that resolves this vulnerability.Fixed in 1.15.15-1~deb11u4 - Upgrade
Upgrade
debian/golang-1.19to a version that resolves this vulnerability.Fixed in 1.19.8-2 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.18.4 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.17.12 - Upgrade
Upgrade
golang/io/fsto a version that resolves this vulnerability.Fixed in 1.17.12 - Upgrade
Upgrade
golang/io/fsto a version that resolves this vulnerability.Fixed in 1.18.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:6113
- RHSA-2022:6345
- RHSA-2022:6188
- RHSA-2022:6430
- RHSA-2023:1042
- RHSA-2022:6040
- RHSA-2022:6042
- RHSA-2022:6152
- RHSA-2022:6348
- RHSA-2022:6346
- RHSA-2022:6347
- RHSA-2022:6370
- RHSA-2023:3642
- RHSA-2022:5866
- RHSA-2022:5775
- RHSA-2022:7129
- RHSA-2022:7519
- RHSA-2022:7529
- RHSA-2022:7648
- RHSA-2023:2758
- RHSA-2023:2802
- RHSA-2022:5799
- RHSA-2022:8057
- RHSA-2022:8098
- RHSA-2022:8250
- RHSA-2023:2357
- RHSA-2022:9047
- RHSA-2022:6283
- RHSA-2023:1275
- RHSA-2023:0407
- RHSA-2023:0408
- RHSA-2023:1529
- IBM-7173596
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2022-30630.
What is the severity of CVE-2022-30630?
The severity of CVE-2022-30630 is high.
What is the affected software?
The affected software includes golang versions up to 1.17.12 and 1.18.4, skupper-cli version up to 1.0.2-2.el8, openshift-serverless-clients version up to 1.3.1-4.el8, go-toolset version up to 1.17-golang-1.17.12-1.el7_9, git-lfs version up to 2.13.3-3.el8_6, grafana versions up to 7.5.15-3.el8 and 7.5.15-3.el9, grafana-pcp versions up to 3.2.0-2.el8 and 3.2.0-3.el9, etcd version up to 3.3.23-12.el8, kubevirt versions up to 4.12.0-1057.el7 and 4.12.0-1057.el8, and Golang Go versions up to 1.17.12 and between 1.18.0 and 1.18.4.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by calling Glob on a path that contains a large number of path separators, causing a panic issue due to stack exhaustion.
How can I fix CVE-2022-30630?
To fix CVE-2022-30630, you need to update golang to version 1.17.12 or 1.18.4, skupper-cli to version 1.0.2-2.el8, openshift-serverless-clients to version 1.3.1-4.el8, go-toolset to version 1.17-golang-1.17.12-1.el7_9, git-lfs to version 2.13.3-3.el8_6, grafana to version 7.5.15-3.el8 or 7.5.15-3.el9, grafana-pcp to version 3.2.0-2.el8 or 3.2.0-3.el9, etcd to version 3.3.23-12.el8, kubevirt to version 4.12.0-1057.el7 or 4.12.0-1057.el8, or Golang Go to version 1.17.12 or between 1.18.0 and 1.18.4.