MEDIUM 5.3 Go

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

GHSA-p782-xgp4-8hr8 · BIT-golang-2022-29526 · CVE-2022-29526 · GO-2022-0493

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Reporting in syscall. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Specific Go Packages Affected

golang.org/x/sys/unix

Ready to move

Start Securing

Free, no credit card | First findings in minutes