Back to bug 2132872

Who When What Removed Added
Avinash Hanwate 2022-10-07 05:02:08 UTC CC amctagga, aoconnor, bniver, bodavis, dbenoit, emachado, flucifre, gmeno, jistone, jpadman, mbenjamin, mhackett, mnewsome, sipoyare, sostapov, tstellar, vereddy
Avinash Hanwate 2022-10-07 05:02:46 UTC CC jwendell, ovanders, rcernich
Avinash Hanwate 2022-10-07 05:04:50 UTC Depends On 2132875, 2132874
Avinash Hanwate 2022-10-07 05:08:26 UTC CC jwendell, ovanders, rcernich
Avinash Hanwate 2022-10-07 05:10:08 UTC Summary CVE-2022-41715 regexp/syntax: limit memory used by parsing regexps CVE-2022-41715 golang: regexp/syntax: limit memory used by parsing regexps
Avinash Hanwate 2022-10-07 05:14:57 UTC CC abishop, agerstmayr, alakatos, ansmith, apevec, bbaude, bbuckingham, bcl, bcoca, bcourt, bkundu, btotty, chazlett, cnv-qe-bugs, cwelton, davidn, dcadzow, debarshir, desktop-qa-list, dkenigsb, dwalsh, eglynn, ehelms, epacific, etamir, fdeutsch, grafana-maint, hchiramm, jaharrin, jburrell, jcammara, jchui, jeder, jhardy, jjoyce, jkurik, jligon, jmulligan, jneedle, jnovy, jobarker, joelsmith, jsherril, jwon, krathod, lball, lhh, lsm5, lzap, mabashia, madam, matzew, mboddu, mburns, mcressma, mgarciac, mheon, mhulan, mmagr, mmccune, mokumar, myarboro, nathans, nbecker, nmoumoul, nobody, ocs-bugs, opohorel, orabin, oramraz, osapryki, osbuilders, pcreech, pehunt, pjindal, pthomas, rchan, rhcos-sst, rhos-maint, rhs-bugs, rhuss, rrajasek, rsroka, saroy, sgott, simaishi, smcdonal, smullick, spower, tkral, tsweeney, umohnani, vkareh, vrothber, yguenane, zsadeh
Avinash Hanwate 2022-10-07 05:15:19 UTC CC amackenz, amasferr, bdettelb, dwhatley, dymurray, gparvin, ibolton, jcantril, jmatthew, jmontleo, jramanat, lmadsen, mkudlej, mrunge, mwringe, nboldt, njean, pahickey, periklis, scorneli, slucidi, sseago, stcannon, tjochec, whayutin
Avinash Hanwate 2022-10-07 05:15:47 UTC CC jwendell, ovanders, rcernich
Sage McTaggart 2022-10-11 20:29:02 UTC CC abishop, amackenz, amasferr, ansmith, apevec, bbuckingham, bcoca, bcourt, bdettelb, bkundu, btotty, chazlett, cnv-qe-bugs, cwelton, davidn, dcadzow, dkenigsb, dwhatley, dymurray, eglynn, ehelms, epacific, etamir, fdeutsch, gparvin, hchiramm, ibolton, jaharrin, jburrell, jcammara, jcantril, jchui, jeder, jhardy, jjoyce, jmatthew, jmontleo, jmulligan, jneedle, jobarker, joelsmith, jramanat, jsherril, jwendell, jwon, krathod, lball, lhh, lmadsen, lzap, mabashia, madam, matzew, mburns, mcressma, mgarciac, mhulan, mkudlej, mmagr, mmccune, mokumar, mrunge, mwringe, myarboro, nbecker, nboldt, njean, nmoumoul, nobody, ocs-bugs, orabin, oramraz, osapryki, ovanders, pahickey, pcreech, periklis, pjindal, rcernich, rchan, rhos-maint, rhs-bugs, rhuss, rrajasek, saroy, scorneli, sgott, simaishi, slucidi, smcdonal, smullick, spower, sseago, stcannon, tjochec, tkral, vkareh, whayutin, yguenane, zsadeh
Sage McTaggart 2022-10-11 20:29:21 UTC CC abishop, ansmith, apevec, bbuckingham, bcoca, bcourt, bkundu, btotty, chazlett, cnv-qe-bugs, cwelton, davidn, dcadzow, dkenigsb, eglynn, ehelms, epacific, etamir, fdeutsch, hchiramm, jaharrin, jburrell, jcammara, jchui, jeder, jhardy, jjoyce, jmulligan, jneedle, jobarker, joelsmith, jsherril, jwon, krathod, lball, lhh, lzap, mabashia, madam, matzew, mburns, mcressma, mgarciac, mhulan, mmagr, mmccune, mokumar, myarboro, nbecker, nmoumoul, nobody, ocs-bugs, orabin, oramraz, osapryki, oskutka, pcreech, pjindal, rchan, rhos-maint, rhs-bugs, rhuss, rrajasek, saroy, sgott, simaishi, smcdonal, smullick, spower, tkral, vkareh, yguenane, zsadeh
Sage McTaggart 2022-10-11 20:29:36 UTC CC amackenz, amasferr, bdettelb, dwhatley, dymurray, gparvin, ibolton, jcantril, jmatthew, jmontleo, jramanat, lmadsen, mkudlej, mrunge, mwringe, nboldt, njean, pahickey, periklis, scorneli, slucidi, sseago, stcannon, tjochec, whayutin
Sage McTaggart 2022-10-11 20:29:58 UTC CC jwendell, ovanders, rcernich
Sage McTaggart 2022-10-11 20:37:28 UTC Depends On 2133925, 2133924, 2133921, 2133923, 2133922, 2133926, 2133917, 2133916, 2133920, 2133927, 2133915
TEJ RATHI 2022-10-13 07:51:27 UTC CC vkumar
Borja Tarraso 2022-10-13 08:06:59 UTC Depends On 2134347
TEJ RATHI 2022-10-13 11:30:34 UTC Depends On 2134407, 2134406, 2134405
TEJ RATHI 2022-10-13 12:33:02 UTC Depends On 2134442, 2134443, 2134441
TEJ RATHI 2022-10-13 12:54:48 UTC Depends On 2134450, 2134445, 2134449, 2134447, 2134446, 2134448
TEJ RATHI 2022-10-13 13:10:42 UTC Depends On 2134453, 2134456, 2134457, 2134454, 2134455
TEJ RATHI 2022-10-13 13:18:33 UTC Depends On 2134468, 2134467
TEJ RATHI 2022-10-13 13:25:38 UTC Depends On 2134473, 2134476, 2134475, 2134471, 2134474, 2134477, 2134472
TEJ RATHI 2022-10-13 13:35:34 UTC Depends On 2134492, 2134495, 2134481, 2134486, 2134497, 2134487, 2134500, 2134488, 2134499, 2134482, 2134483, 2134485, 2134484, 2134494, 2134493, 2134490, 2134491, 2134501, 2134498, 2134496, 2134489
Borja Tarraso 2022-10-13 13:52:24 UTC CC bbuckingham, bcourt, btotty, ehelms, jsherril, lzap, mhulan, mmccune, myarboro, nmoumoul, orabin, pcreech, rchan
Nick Tait 2022-10-15 19:43:01 UTC CC cnv-qe-bugs, sgott
Stoyan Nikolov 2022-10-17 08:55:19 UTC Depends On 2133921
Avinash Hanwate 2022-10-18 09:32:20 UTC Depends On 2135726, 2135724, 2135727, 2135725
Ondřej Pohořelský 2022-10-20 11:10:41 UTC CC opohorel
Tomáš Král 2022-10-21 07:26:39 UTC CC tkral
David Benoit 2022-10-21 14:33:46 UTC Depends On 2136835
David Benoit 2022-10-21 15:11:14 UTC Depends On 2136839
David Benoit 2022-10-21 15:11:53 UTC Depends On 2136841
David Benoit 2022-10-21 15:23:12 UTC Depends On 2136843
David Benoit 2022-10-21 15:31:55 UTC Depends On 2136849
Mauro Matteo Cascella 2022-10-24 10:52:55 UTC Depends On 2136717
Mauro Matteo Cascella 2022-10-24 10:53:03 UTC Depends On 2136718
Mauro Matteo Cascella 2022-10-24 10:53:11 UTC Depends On 2136719
Mauro Matteo Cascella 2022-10-24 10:53:21 UTC Depends On 2136720
Mauro Matteo Cascella 2022-10-24 10:53:41 UTC Depends On 2136721
Mauro Matteo Cascella 2022-10-24 10:53:52 UTC Depends On 2136722
Mauro Matteo Cascella 2022-10-24 10:54:01 UTC Depends On 2136723
Red Hat Bugzilla 2022-10-28 13:12:46 UTC CC krathod
Vipul Nair 2022-10-31 15:22:21 UTC Depends On 2138893, 2138892
Avinash Hanwate 2022-11-01 04:11:10 UTC CC adudiak, tfister
Doc Text A flaw was found in the golang package. Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexp consume much larger amounts of memory. After the fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.
RaTasha Tillery-Smith 2022-11-01 12:27:05 UTC Doc Text A flaw was found in the golang package. Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexp consume much larger amounts of memory. After the fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected. A flaw was found in the golang package, where programs that compile regular expressions from untrusted sources are vulnerable to memory exhaustion or a denial of service. The parsed regexp representation is linear in the input size. Still, in some cases, the constant factor can be as high as 40,000, making a relatively small regexp consume larger amounts of memory. After the fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Routine use of regular expressions is unaffected.
errata-xmlrpc 2022-12-08 07:38:00 UTC Link ID Red Hat Product Errata RHSA-2022:8781
Red Hat Bugzilla 2022-12-31 20:04:29 UTC CC hchiramm
Red Hat Bugzilla 2023-01-01 05:32:38 UTC CC amctagga
Red Hat Bugzilla 2023-01-01 05:47:07 UTC CC flucifre
Red Hat Bugzilla 2023-01-01 05:52:42 UTC CC mhackett
Red Hat Bugzilla 2023-01-01 06:02:03 UTC CC bniver
Red Hat Bugzilla 2023-01-01 08:30:35 UTC CC jmulligan
Red Hat Bugzilla 2023-01-01 08:34:11 UTC CC mbenjamin
Red Hat Bugzilla 2023-01-01 08:43:11 UTC CC sostapov
Red Hat Bugzilla 2023-01-01 08:47:42 UTC CC vereddy
Alasdair Kergon 2023-01-04 04:55:31 UTC CC hchiramm
Alasdair Kergon 2023-01-04 05:43:50 UTC CC sostapov
Alasdair Kergon 2023-01-04 06:11:25 UTC CC bniver
Alasdair Kergon 2023-01-04 06:19:28 UTC CC mbenjamin
Alasdair Kergon 2023-01-04 06:29:04 UTC CC vereddy
Alasdair Kergon 2023-01-04 06:43:51 UTC CC flucifre
Alasdair Kergon 2023-01-04 11:29:24 UTC CC mhackett
Sam Fowler 2023-01-13 00:15:22 UTC CC sfowler
errata-xmlrpc 2023-01-17 14:51:36 UTC Link ID Red Hat Product Errata RHSA-2022:7398
errata-xmlrpc 2023-01-17 19:37:34 UTC Link ID Red Hat Product Errata RHSA-2022:7399
errata-xmlrpc 2023-01-19 11:04:42 UTC Link ID Red Hat Product Errata RHSA-2023:0264
Victor Kareh 2023-01-19 19:17:09 UTC CC vkareh
Red Hat Bugzilla 2023-01-20 05:18:42 UTC CC cwelton
errata-xmlrpc 2023-01-23 15:20:42 UTC Link ID Red Hat Product Errata RHSA-2023:0328
errata-xmlrpc 2023-01-25 08:31:19 UTC Link ID Red Hat Product Errata RHSA-2023:0445
errata-xmlrpc 2023-01-25 09:16:02 UTC Link ID Red Hat Product Errata RHSA-2023:0446
errata-xmlrpc 2023-01-30 17:21:08 UTC Link ID Red Hat Product Errata RHSA-2023:0542
Red Hat Bugzilla 2023-01-31 22:27:08 UTC CC nbecker
Red Hat Bugzilla 2023-01-31 22:28:01 UTC CC etamir
Red Hat Bugzilla 2023-01-31 23:37:36 UTC CC madam
Josh Stone 2023-02-02 02:06:44 UTC CC jistone
Red Hat Bugzilla 2023-02-03 23:11:32 UTC CC ovanders
errata-xmlrpc 2023-02-07 17:24:17 UTC Link ID Red Hat Product Errata RHSA-2023:0631
Red Hat Bugzilla 2023-02-08 00:54:40 UTC CC hchiramm
errata-xmlrpc 2023-02-09 02:17:34 UTC Link ID Red Hat Product Errata RHSA-2023:0693
Yadnyawalk Tale 2023-02-09 07:50:31 UTC CC ytale
errata-xmlrpc 2023-02-09 09:26:20 UTC Link ID Red Hat Product Errata RHSA-2023:0708
errata-xmlrpc 2023-02-09 12:05:47 UTC Link ID Red Hat Product Errata RHSA-2023:0709
Yadnyawalk Tale 2023-02-10 05:05:17 UTC Depends On 2168805
errata-xmlrpc 2023-02-16 14:14:21 UTC Link ID Red Hat Product Errata RHSA-2023:0727
Red Hat Bugzilla 2023-02-22 01:15:34 UTC CC dkenigsb
errata-xmlrpc 2023-03-06 16:24:49 UTC Link ID Red Hat Product Errata RHSA-2023:1079
errata-xmlrpc 2023-03-06 18:41:02 UTC Link ID Red Hat Product Errata RHSA-2023:1042
errata-xmlrpc 2023-03-09 01:25:09 UTC Link ID Red Hat Product Errata RHSA-2023:1174
Red Hat Bugzilla 2023-03-15 08:33:29 UTC CC rhs-bugs
errata-xmlrpc 2023-03-15 19:56:16 UTC Link ID Red Hat Product Errata RHSA-2023:1275
errata-xmlrpc 2023-03-30 00:44:08 UTC Link ID Red Hat Product Errata RHSA-2023:1529
errata-xmlrpc 2023-05-09 07:13:53 UTC Link ID Red Hat Product Errata RHSA-2023:2167
errata-xmlrpc 2023-05-09 07:17:59 UTC Link ID Red Hat Product Errata RHSA-2023:2204
errata-xmlrpc 2023-05-09 07:35:28 UTC Link ID Red Hat Product Errata RHSA-2023:2357
errata-xmlrpc 2023-05-09 08:02:20 UTC Link ID Red Hat Product Errata RHSA-2023:2592
Red Hat Bugzilla 2023-05-15 18:03:41 UTC CC rrajasek
Red Hat Bugzilla 2023-05-15 18:50:49 UTC CC dcadzow
errata-xmlrpc 2023-05-16 08:11:57 UTC Link ID Red Hat Product Errata RHSA-2023:2780
errata-xmlrpc 2023-05-16 08:12:25 UTC Link ID Red Hat Product Errata RHSA-2023:2784
errata-xmlrpc 2023-05-16 08:22:07 UTC Link ID Red Hat Product Errata RHSA-2023:2866
Red Hat Bugzilla 2023-05-16 09:27:31 UTC CC mokumar
errata-xmlrpc 2023-05-18 02:55:36 UTC Link ID Red Hat Product Errata RHSA-2023:3205
errata-xmlrpc 2023-05-18 14:28:02 UTC Link ID Red Hat Product Errata RHSA-2023:0584
Product Security DevOps Team 2023-05-18 19:43:35 UTC Resolution --- ERRATA
Status NEW CLOSED
Last Closed 2023-05-18 19:43:35 UTC
errata-xmlrpc 2023-06-15 16:01:19 UTC Link ID Red Hat Product Errata RHSA-2023:3642
errata-xmlrpc 2023-06-19 10:33:16 UTC Link ID Red Hat Product Errata RHSA-2023:3664
Joel Smith 2023-06-21 15:50:45 UTC CC joelsmith
errata-xmlrpc 2023-06-22 19:52:04 UTC Link ID Red Hat Product Errata RHSA-2023:3742
errata-xmlrpc 2023-06-26 01:16:03 UTC Link ID Red Hat Product Errata RHSA-2023:3613
errata-xmlrpc 2023-07-10 08:51:13 UTC Link ID Red Hat Product Errata RHSA-2023:4003
Chess Hazlett 2023-07-17 19:01:12 UTC CC ataylor, jross, rkieley

Back to bug 2132872