CVE-2022-30580

unknown
Published 2022-07-26 · Modified 2024-05-20
CVSS v3
CVSS v2
VIR risk

Description

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-30580

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2022-30580.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbullseyefixed0

Package impact

EcosystemPackageVulnerableFixed
golang Gostdlib>=1.18.0-0,<1.18.31.17.11

References

Verify integrity in audit chain (admin only). AS-IS.