VDB
RHSA-2022:6152
RHSA-2022:6152
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in golang. Calling Unmarshal on an XML document into a Go struct, which has a nested field that uses the "any" field tag, can cause a panic due to stack exhaustion.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| golang | go | |
| Red Hat | openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64 as a component of OSSO 1.1 for RHEL 8 | openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64, openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64, openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64 |
| Red Hat | openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64 as a component of OSSO 1.1 for RHEL 8 | |
| Red Hat | openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64 as a component of OSSO 1.1 for RHEL 8 | openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64, openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64, openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:777bb9e4d92ca645fb10cb85d3d0bbc35408e63d0dbddee200a85a018b6afc69_amd64 |
| Red Hat | openshift-secondary-scheduler-operator/secondary-scheduler-operator-bundle@sha256:752fb4e99e8d8dee18579aba58f34d5248822e77590a51c0d72ecbc726c90a4e_amd64 as a component of OSSO 1.1 for RHEL 8 | openshift-secondary-scheduler-operator/secondary-scheduler-operator-bundle@sha256:752fb4e99e8d8dee18579aba58f34d5248822e77590a51c0d72ecbc726c90a4e_amd64, *, * |
| Red Hat | openshift-secondary-scheduler-operator/secondary-scheduler-operator-bundle@sha256:752fb4e99e8d8dee18579aba58f34d5248822e77590a51c0d72ecbc726c90a4e_amd64 as a component of OSSO 1.1 for RHEL 8 | openshift-secondary-scheduler-operator/secondary-scheduler-operator-bundle@sha256:752fb4e99e8d8dee18579aba58f34d5248822e77590a51c0d72ecbc726c90a4e_amd64, *, openshift-secondary-scheduler-operator/secondary-scheduler-operator-bundle@sha256:752fb4e99e8d8dee18579aba58f34d5248822e77590a51c0d72ecbc726c90a4e_amd64 |
Timeline
- Sep 1, 2022 CVE Published
- Apr 25, 2026 Security Advisory
- Apr 26, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
- May 3, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 6, 2026 Distribution Patch
- May 7, 2026 Distribution Patch
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-30630 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2107383 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2105001 issue
- https://issues.redhat.com/browse/WRKLDS-466 advisory
- https://access.redhat.com/security/cve/CVE-2022-1705 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1705 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-28131 advisory
- https://access.redhat.com/security/cve/CVE-2022-30631 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-30631 advisory
- https://access.redhat.com/security/cve/CVE-2022-30632 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-30633 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://go.dev/issue/53188 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-28327 advisory
- https://go.dev/issue/53611 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-30635 advisory
- https://access.redhat.com/security/cve/CVE-2022-32148 advisory
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-24675 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2107376 issue
…and 45 more