← Back

CVE-2022-41724

nvd nist
Published: Feb 28, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).

Affected (5)

Products: Golang: Go
1 product
Go
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Golang
Before 1.19.6
Version 1.20.0
Version 1.20.0 rc1
Version 1.20.0 rc2
Version 1.20.0 rc3

References (10)

Source: security@golang.org
PatchRelease Notes
Source: security@golang.org
Issue TrackingPatchVendor Advisory
Source: security@golang.org
Mailing ListVendor Advisory
Source: security@golang.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.