Name
CVE-2022-27664
Description
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://groups.google.com/g/golang-announceMailing List
https://security.gentoo.org/glsa/202209-26Third Party Advisory
https://security.netapp.com/advisory/ntap-20220923-0004/Third Party Advisory
https://groups.google.com/g/golang-announceMailing List
https://security.gentoo.org/glsa/202209-26Third Party Advisory
https://security.netapp.com/advisory/ntap-20220923-0004/Third Party Advisory
Analysis#
Vulnerability Rating#
7.5
CVSSv31
Others affected components#
Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Not Affected
openwrt
master
1.26.4-r1
Not Affected
openwrt
openwrt-25.12
1.24.13-r1
Not Affected
openwrt
openwrt-25.12
1.26.4-r1
Not Affected
yocto
master
1.26.4
Not Affected
yocto
master
1.26.4
Not Affected
yocto
scarthgap
1.22.12
Not Affected
yocto
scarthgap
1.22.12
Not Affected