crypto/internal/fips140: CVE-2022-29526 reported in golang.org/x/sys #71936
Labels
NeedsInvestigation
Someone must examine and confirm this is a valid issue and not a duplicate of an existing one.
vulncheck or vulndb
Issues for the x/vuln or x/vulndb repo
I believe CVE-2022-29526 is already fixed in the current go version, however, when you download and extract the current Go v1.24.0, this CVE is reported due to the version of
golang.org/x/sys
reported in/usr/local/go/src/crypto/internal/fips140/bigmod/_asm/go.mod
and/usr/local/go/src/crypto/internal/fips140/edwards25519/field/_asm/go.mod
, which appears as follows:It looks as though someone tried to submit a PR to fix some time ago, but nothing happened with it. #62452
The text was updated successfully, but these errors were encountered: