[GO-2022-0477] Indefinite hang with large buffers on Windows in crypto/rand

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

On Windows, rand.Read will hang indefinitely if passed a buffer larger than 1 <<
32 - 1 bytes.

Package Affected Version
pkg:golang/crypto/rand >= 1.18.0, < 1.17.11
pkg:golang/crypto/rand >= 1.18.0, < 1.18.3
Package Fixed Version
pkg:golang/crypto/rand = 1.17.11
pkg:golang/crypto/rand = 1.18.3
ID
GO-2022-0477
Severity
high
Severity from
CVE-2022-30634
URL
https://pkg.go.dev/vuln/GO-2022-0477
Published
2022-08-12T17:19:52
(2 years ago)
Modified
2024-07-17T19:54:18
(2 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/crypto/rand crypto rand = 1.17.11
Affected pkg:golang/crypto/rand crypto rand >= 1.18.0 < 1.17.11
Fixed pkg:golang/crypto/rand crypto rand = 1.18.3
Affected pkg:golang/crypto/rand crypto rand >= 1.18.0 < 1.18.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...