regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. Reference: https://groups.google.com/g/golang-announce/c/RP1hfrBYVuk
Created golang tracking bugs for this issue: Affects: epel-all [bug 2066512] Affects: openstack-rdo [bug 2066513]
This issue has been addressed in the following products: Red Hat Developer Tools Via RHSA-2022:5415 https://access.redhat.com/errata/RHSA-2022:5415
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.10 Via RHSA-2022:5729 https://access.redhat.com/errata/RHSA-2022:5729
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.10 Via RHSA-2022:5730 https://access.redhat.com/errata/RHSA-2022:5730
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Ironic content for Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:5068 https://access.redhat.com/errata/RHSA-2022:5068
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2022:6042 https://access.redhat.com/errata/RHSA-2022:6042
This issue has been addressed in the following products: Openshift Serveless 1.24 Via RHSA-2022:6040 https://access.redhat.com/errata/RHSA-2022:6040
Could someone please confirm which go 1.18 version addresses/is free from this vulnerability?
This issue has been addressed in the following products: Red Hat OpenShift Data Foundation 4.11 on RHEL8 Via RHSA-2022:6156 https://access.redhat.com/errata/RHSA-2022:6156
This issue has been addressed in the following products: OpenShift Service Mesh 2.1 Via RHSA-2022:6277 https://access.redhat.com/errata/RHSA-2022:6277
This issue has been addressed in the following products: RHEL-8-CNV-4.11 Via RHSA-2022:6526 https://access.redhat.com/errata/RHSA-2022:6526
This issue has been addressed in the following products: RHACS-3.72-RHEL-8 Via RHSA-2022:6714 https://access.redhat.com/errata/RHSA-2022:6714
This issue has been addressed in the following products: RHEL-8-CNV-4.11 Via RHSA-2022:8750 https://access.redhat.com/errata/RHSA-2022:8750
This issue has been addressed in the following products: RHEL-8-CNV-4.12 RHEL-7-CNV-4.12 Via RHSA-2023:0407 https://access.redhat.com/errata/RHSA-2023:0407
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-24921