CVE-2022-28327
20.04.2022, 10:15
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.Enginsight
Vendor | Product | Version |
---|---|---|
golang | go | 𝑥 < 1.17.9 |
golang | go | 1.18.0 ≤ 𝑥 < 1.18.1 |
fedoraproject | extra_packages_for_enterprise_linux | 7.0 |
fedoraproject | extra_packages_for_enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
golang-1.17 |
| ||||||||||||||||||
golang-1.18 |
|
References