Vulnerability Description
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.19.10 |
| Fedoraproject | Fedora | 38 |
Related Weaknesses (CWE)
References
- https://go.dev/cl/501223Patch
- https://go.dev/issue/60272Issue Tracking
- https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJMailing ListRelease Notes
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://pkg.go.dev/vuln/GO-2023-1840Vendor Advisory
- https://security.gentoo.org/glsa/202311-09
- https://go.dev/cl/501223Patch
- https://go.dev/issue/60272Issue Tracking
- https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJMailing ListRelease Notes
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://pkg.go.dev/vuln/GO-2023-1840Vendor Advisory
- https://security.gentoo.org/glsa/202311-09
- https://security.netapp.com/advisory/ntap-20241220-0009/
FAQ
What is CVE-2023-29403?
CVE-2023-29403 is a vulnerability with a CVSS score of 7.8 (HIGH). On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming t...
How severe is CVE-2023-29403?
CVE-2023-29403 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-29403?
Check the references section above for vendor advisories and patch information. Affected products include: Golang Go, Fedoraproject Fedora.