UBUNTU-CVE-2022-27664
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-27664
UBUNTU-CVE-2022-27664
Summary:
Details: In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
References: https://ubuntu.com/security/CVE-2022-27664, https://groups.google.com/g/golang-announce/c/x49AQzIVX-s, https://github.com/golang/go/issues/54658, https://github.com/golang/go/commit/9cfe4e258b1c9d4a04a42539c21c7bdb2e227824, https://github.com/golang/go/commit/5bc9106458fc07851ac324a4157132a91b1f3479, https://groups.google.com/g/golang-announce, https://ubuntu.com/security/notices/USN-6038-1, https://ubuntu.com/security/notices/USN-6038-2, https://www.cve.org/CVERecord?id=CVE-2022-27664, https://ubuntu.com/security/notices/USN-8089-1, https://ubuntu.com/security/notices/USN-8089-2, https://ubuntu.com/security/notices/USN-8089-3
Affected packages
Package
Name: golang-1.10
Purl: pkg:deb/ubuntu/golang-1.10?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
