Medium severity5.5NVD Advisory· Published Feb 28, 2023· Updated Jun 17, 2026
CVE-2022-41727
CVE-2022-41727
Description
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
golang.org/x/imageGo | < 0.5.0 | 0.5.0 |
Affected products
6- golang.org/x/image/golang.org/x/image/tiffv5Range: 0
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- go.dev/cl/468195nvdPatchWEB
- github.com/advisories/GHSA-qgc7-mgm3-q253ghsaADVISORY
- groups.google.com/g/golang-announce/c/ag-FiyjlD5onvdMailing ListVendor AdvisoryWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/KO54NBDUJXKAZNGCFOEYL2LKK2RQP6K6/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/XWH6Q7NVM4MV3GWFEU4PA67AWZHVFJQ2/nvdMailing ListThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2022-41727ghsaADVISORY
- pkg.go.dev/vuln/GO-2023-1572nvdVendor AdvisoryWEB
- go.dev/issue/58003nvdIssue TrackingWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/KO54NBDUJXKAZNGCFOEYL2LKK2RQP6K6ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/XWH6Q7NVM4MV3GWFEU4PA67AWZHVFJQ2ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/XZTEP6JYILRBNDTNWTEQ5D4QUUVQBESKghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/XZTEP6JYILRBNDTNWTEQ5D4QUUVQBESK/nvd
News mentions
0No linked articles in our index yet.