CVE-2022-3064
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
5.5
Description
RHSA-2024:10784: rhc security update (Moderate)
Predictions
Exploit likelihood
30%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
AlmaLinux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | toolbox-0.0.99.4-6.el9_3.ppc64le.rpm |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2.2.8-1 |
| sid | Fixed | 2.2.8-1 |
| forky | Fixed | 2.2.8-1 |
| bullseye | Fixed | 2.2.8-1 |
| bookworm | Fixed | 2.2.8-1 |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | โ |
| 8 | Fixed | โ |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | โ |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | gopkg.in/yaml.v2 | <2.2.4 | 2.2.4 |
References
- https://errata.rockylinux.org/RLSA-2023:6938
- https://errata.rockylinux.org/RLSA-2023:6939
- https://access.redhat.com/errata/RHSA-2023:6346
- https://access.redhat.com/errata/RHSA-2024:10759
- https://nvd.nist.gov/vuln/detail/CVE-2022-3064
- https://github.com/go-yaml/yaml/commit/f221b8435cfb71e54062f6c6e99e9ade30b124d5
- https://github.com/go-yaml/yaml
- https://github.com/go-yaml/yaml/releases/tag/v2.2.4
- https://lists.debian.org/debian-lts-announce/2023/07/msg00001.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4SBIUECMLNC572P23DDOKJNKPJVX26SP
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ANIOPUXWIHVRA6CEWXCGOMX3YYS6KFHG
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PW3XC47AUW5J5M2ULJX7WCCL3B2ETLMT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI
- https://pkg.go.dev/vuln/GO-2022-0956
- https://security-tracker.debian.org/tracker/CVE-2022-3064
- https://access.redhat.com/errata/RHSA-2023:6938
- https://bugzilla.redhat.com/2163037
- https://bugzilla.redhat.com/2175721
- https://bugzilla.redhat.com/2178358
- https://bugzilla.redhat.com/2178488
- https://bugzilla.redhat.com/2178492
- https://bugzilla.redhat.com/2182883
- https://bugzilla.redhat.com/2182884
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.