-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The GitHub issue #52313 explicitly identifies a logic error in syscall.Faccessat's group membership check where it uses the process's gid instead of the file's st.Gid. This matches CVE-2022-29526's description of incorrect privilege reporting when flags parameter is non-zero. Both the standard library syscall and golang.org/x/sys/unix implementations are affected as they share the vulnerable code path.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| golang.org/x/sys | go | < 0.0.0-20220412211240-33da011f77ad | 0.0.0-20220412211240-33da011f77ad |
Ongoing coverage of React2Shell