Back

HIGH

Stack exhaustion when decoding certain messages in encoding/gob

Published Aug 9, 2022

Description

Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform (OCP) starting from 4.10 stream is already compiled in the patched version of Go, hence is not affected by this vulnerability.The vulnerability has been rated as moderate instead of high because the vulnerability can only result in a minor denial of service.

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Go
Published Aug 9, 2022
Updated Mar 6, 2026
Reserved May 12, 2022
CISA Vulnrichment
Updated Mar 6, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 12, 2022
ENISA EUVD
Assigner Go
Published Aug 9, 2022
Updated Mar 6, 2026
Exploited since n/a
EUVD-2022-52466