CVE-2022-32189
Panic when decoding Float and Rat types in math/big
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
Un mensaje codificado demasiado corto puede causar un pánico en Float.GobDecode y Rat GobDecode en math/big en Go versiones anteriores a 1.17.13 y 1.18.5, permitiendo potencialmente una denegación de servicio
An uncontrolled resource consumption flaw was found in Golang math/big. A too-short encoded message can cause a panic in Float.GobDecode and Rat.GobDecode in math/big in Go, potentially allowing an attacker to create a denial of service, impacting availability.
Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services. This new container image is based on Red Hat Ceph Storage 6.1 and Red Hat Enterprise Linux 9. Issues addressed include bypass, cross site scripting, denial of service, information leakage, spoofing, and traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-31 CVE Reserved
- 2022-08-04 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://groups.google.com/g/golang-announce/c/YqYYG87xB10 | Mailing List |
URL | Date | SRC |
---|---|---|
https://go.dev/issue/53871 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://go.dev/cl/417774 | 2023-03-03 | |
https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66 | 2023-03-03 |
URL | Date | SRC |
---|---|---|
https://pkg.go.dev/vuln/GO-2022-0537 | 2023-03-03 | |
https://access.redhat.com/security/cve/CVE-2022-32189 | 2024-05-21 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2113814 | 2024-05-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Golang Search vendor "Golang" | Go Search vendor "Golang" for product "Go" | < 1.17.13 Search vendor "Golang" for product "Go" and version " < 1.17.13" | - |
Affected
| ||||||
Golang Search vendor "Golang" | Go Search vendor "Golang" for product "Go" | >= 1.18.0 < 1.18.5 Search vendor "Golang" for product "Go" and version " >= 1.18.0 < 1.18.5" | - |
Affected
|