CVE-2022-3064: Excessive resource consumption in gopkg.in/yaml.v2
A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.
Other sources
Excessive resource consumption in gopkg.in/yaml.v2
— Microsoft
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/etcdto a version that resolves this vulnerability.Fixed in 0:3.3.23-12.el8 - Upgrade
Upgrade
redhat/etcdto a version that resolves this vulnerability.Fixed in 0:3.4.14-3.el9 - Upgrade
Upgrade
ubuntu/golang-yaml.v2to a version that resolves this vulnerability.Fixed in 2.2.4 - Upgrade
Upgrade
ubuntu/golang-yaml.v2to a version that resolves this vulnerability.Fixed in 0.0+ - Upgrade
Upgrade
ubuntu/golang-yaml.v2to a version that resolves this vulnerability.Fixed in 2.2.2-1ubuntu0.1 - Upgrade
Upgrade
debian/golang-yaml.v2to a version that resolves this vulnerability.Fixed in 2.2.2-1+deb10u1Fixed in 2.4.0-1Fixed in 2.4.0-4 - Upgrade
Upgrade
go/gopkg.in/yaml.v2to a version that resolves this vulnerability.Fixed in 2.2.4 - Upgrade
Upgrade
redhat/gopkg.in/yaml.v2to a version that resolves this vulnerability.Fixed in 2.2.4 - Upgrade
Upgrade
gopkg.in/yaml.v2 (go-yaml)to a version that resolves this vulnerability.Fixed in v2.2.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch GO-2022-0956
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-3064?
CVE-2022-3064 is a vulnerability that can cause the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.
What is the severity of CVE-2022-3064?
The severity of CVE-2022-3064 is high, with a CVSS score of 7.5.
Which software is affected by CVE-2022-3064?
The affected software includes go-yaml version up to 2.2.4, golang-yaml.v2 up to version 2.2.4 on Ubuntu, golang-yaml.v2 version up to 2.2.2-1ubuntu0.1 on Ubuntu Focal, golang-yaml.v2 version up to 0.0+ on Ubuntu Xenial, golang-yaml.v2 version up to 0.0+ on Ubuntu Bionic, golang-yaml.v2 version up to 2.2.2-1 on Debian, gopkg.in/yaml.v2 version up to 2.2.4 on Red Hat, etcd version up to 3.3.23-12.el8 on Red Hat, etcd version up to 3.4.14-3.el9 on Red Hat, and gopkg.in/yaml.v2 version up to 2.2.4 on Go.
How can I fix CVE-2022-3064 in go-yaml version up to 2.2.4?
To fix CVE-2022-3064 in go-yaml, you should update to version 2.2.4 or later.
Where can I find more information about CVE-2022-3064?
You can find more information about CVE-2022-3064 at the following references: [Link 1](https://github.com/go-yaml/yaml/commit/f221b8435cfb71e54062f6c6e99e9ade30b124d5), [Link 2](https://github.com/go-yaml/yaml/releases/tag/v2.2.4), [Link 3](https://lists.debian.org/debian-lts-announce/2023/07/msg00001.html).