Lucene search

K
osvGoogleOSV:GHSA-P782-XGP4-8HR8
HistoryJun 24, 2022 - 12:00 a.m.

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

2022-06-2400:00:30
Google
osv.dev
11
golang
unix syscall
privilege reporting
faccessat
file accessible
software security

AI Score

7.5

Confidence

Low

EPSS

0.002

Percentile

64.7%

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Reporting in syscall. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Specific Go Packages Affected

golang.org/x/sys/unix