​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-2fhw-5629-6ffq

Published

Last updated

https://images.chainguard.dev/security/CGA-2fhw-5629-6ffq
Package

dynamic-localpv-provisioner

Latest Update
Fixed
Fixed Version

3.4.1-r3

Aliases
  • CVE-2022-29526
  • GHSA-p782-xgp4-8hr8

Severity

5.3

Medium

CVSS V3

Summary

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Description

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Reporting in syscall. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Specific Go Packages Affected

golang.org/x/sys/unix

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images