rpm package
suse/google-guest-agent&distro=SUSE Linux Enterprise Module for Public Cloud 12
pkg:rpm/suse/google-guest-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-22868 | — | < 20250116.00-1.47.2 | 20250116.00-1.47.2 | Feb 26, 2025 | An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing. | ||
| CVE-2024-45337 | Cri | 9.1 | < 20250327.01-1.50.1 | 20250327.01-1.50.1 | Dec 12, 2024 | Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that | |
| CVE-2022-23806 | — | < 20230221.00-1.29.1 | 20230221.00-1.29.1 | Feb 11, 2022 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. | ||
| CVE-2021-38297 | — | < 20230221.00-1.29.1 | 20230221.00-1.29.1 | Oct 18, 2021 | Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used. |
- CVE-2025-22868Feb 26, 2025affected < 20250116.00-1.47.2fixed 20250116.00-1.47.2
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
- affected < 20250327.01-1.50.1fixed 20250327.01-1.50.1
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that
- CVE-2022-23806Feb 11, 2022affected < 20230221.00-1.29.1fixed 20230221.00-1.29.1
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
- CVE-2021-38297Oct 18, 2021affected < 20230221.00-1.29.1fixed 20230221.00-1.29.1
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.