golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Overview

Source
ID
GHSA-p782-xgp4-8hr8
Aliases
BIT-golang-2022-29526
CVE-2022-29526
GO-2022-0493
Affected package

Description

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Reporting in syscall. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

### Specific Go Packages Affected golang.org/x/sys/unix

Summary

138.47k
Total packages affected
Packages with at least one version that is affected by the advisory or has an affected dependency.
15.85k
Packages with a known fix
Packages with versions affected by the advisory that have a greater version that is not affected.
10.51%
Total ecosystem affected
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20220412211240-33da011f77ad
Patched/Unaffected
v0.24.0
v0.25.0
v0.26.0
v0.27.0
v0.28.0
v0.29.0
Affected