Bugzilla – Bug 1208858
VUL-0: CVE-2022-41727: buildah,cni-plugins,containerd,cri-o,skopeo: golang.org/x/image: Uncontrolled Resource Consumption
Last modified: 2023-03-02 16:20:47 UTC
+++ This bug was initially created as a clone of Bug #1208853 +++ CVE-2022-41727 An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service. https://go.dev/cl/468195 https://go.dev/issue/58003 https://groups.google.com/g/golang-announce/c/ag-FiyjlD5o https://pkg.go.dev/vuln/GO-2023-1572 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41727 https://bugzilla.redhat.com/show_bug.cgi?id=2174311 https://www.cve.org/CVERecord?id=CVE-2022-41727 https://go.dev/cl/468195 https://go.dev/issue/58003 https://groups.google.com/g/golang-announce/c/ag-FiyjlD5o https://pkg.go.dev/vuln/GO-2023-1572
Our scanners show golang.org/x/image with version < 0.5.0 embedded in: - SUSE:SLE-15-SP1:Update/buildah - SUSE:SLE-15-SP3:Update/buildah - SUSE:SLE-15-SP4:Update/buildah - openSUSE:Factory/buildah - SUSE:SLE-15-SP5:Update/cni-plugins - openSUSE:Factory/cni-plugins - SUSE:SLE-12:Update/containerd - SUSE:SLE-15:Update/containerd - openSUSE:Factory/containerd
Also for cri-o: - SUSE:SLE-15-SP1:Update:Products:CASP40:Update/cri-o - openSUSE:Factory/cri-o
And skopeo: - SUSE:SLE-15-SP1:Update/skopeo - SUSE:SLE-15:Update/skopeo - openSUSE:Factory/skopeo
Sorry, we discovered that these were all false positives. Closing invalid