Unrated severityNVD Advisory· Published Jan 1, 2022· Updated Aug 4, 2024
CVE-2021-44717
CVE-2021-44717
Description
Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.
Affected products
40- Go/Godescription
- osv-coords39 versionspkg:bitnami/golangpkg:rpm/almalinux/delvepkg:rpm/almalinux/golangpkg:rpm/almalinux/golang-binpkg:rpm/almalinux/golang-docspkg:rpm/almalinux/golang-miscpkg:rpm/almalinux/golang-racepkg:rpm/almalinux/golang-srcpkg:rpm/almalinux/golang-testspkg:rpm/almalinux/go-toolsetpkg:rpm/opensuse/apptainer&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/apptainer&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/go1.16&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.16&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/go1.16&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/go1.17&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/go1.17&distro=openSUSE%20Tumbleweedpkg:rpm/suse/go1.16&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3pkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/go1.16&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/go1.16&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/go1.16&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/go1.17&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/go1.17&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/go1.17&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/go1.17&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.17&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3pkg:rpm/suse/go1.17&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/go1.17&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/go1.17&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/go1.17&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/go1.17&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/go1.17&distro=SUSE%20Manager%20Server%204.1
< 1.16.12+ 38 more
- (no CPE)range: < 1.16.12
- (no CPE)range: < 1.6.0-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.16.12-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.16.12-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.16.12-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.16.12-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.16.12-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.16.12-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.16.12-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.16.12-1.module_el8.5.0+2604+960c7771
- (no CPE)range: < 1.1.2-lp154.2.1
- (no CPE)range: < 1.0.1-1.1
- (no CPE)range: < 1.16.12-lp152.20.1
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.1
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.1
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.16.12-1.37.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
- (no CPE)range: < 1.17.5-1.14.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- security.gentoo.org/glsa/202208-02mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2022/01/msg00016.htmlmitremailing-list
- lists.debian.org/debian-lts-announce/2022/01/msg00017.htmlmitremailing-list
- lists.debian.org/debian-lts-announce/2023/04/msg00021.htmlmitremailing-list
- cert-portal.siemens.com/productcert/pdf/ssa-744259.pdfmitre
- groups.google.com/g/golang-announce/c/hcmEScgc00kmitre
News mentions
0No linked articles in our index yet.