Bug 1201434 - (CVE-2022-1705) VUL-0: CVE-2022-1705: go1.17,go1.18: net/http: improper sanitization of Transfer-Encoding header
(CVE-2022-1705)
VUL-0: CVE-2022-1705: go1.17,go1.18: net/http: improper sanitization of Trans...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Jeff Kowalczyk
Security Team bot
CVSSv3.1:SUSE:CVE-2022-1705:5.3:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-07-12 22:17 UTC by Jeff Kowalczyk
Modified: 2022-08-04 16:19 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeff Kowalczyk 2022-07-12 22:17:50 UTC
The HTTP/1 client accepted some invalid Transfer-Encoding headers as indicating a "chunked" encoding. This could potentially allow for request smuggling, but only if combined with an intermediate server that also improperly failed to reject the header as invalid.

This is CVE-2022-1705 and https://go.dev/issue/53188.

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-1705
Comment 1 Jeff Kowalczyk 2022-07-12 23:32:46 UTC
The previous NIST reference is incorrect, please disrgard. Valid references will be available at a later date.
Comment 3 Hu 2022-07-13 11:35:55 UTC
I think go1.15 and go1.16 are affected as well, as they also trim whitespaces, but let me know if I am mistaken:
- SUSE:SLE-15:Update/go1.15  1.15.15
- openSUSE:Factory/go1.15    1.15.15
- SUSE:SLE-15:Update/go1.16  1.16.15
- openSUSE:Factory/go1.16    1.16.15
Comment 4 Jeff Kowalczyk 2022-07-13 20:26:23 UTC
(In reply to Hu from comment #3)
> I think go1.15 and go1.16 are affected as well, as they also trim
> whitespaces, but let me know if I am mistaken:
> - SUSE:SLE-15:Update/go1.15  1.15.15
> - openSUSE:Factory/go1.15    1.15.15
> - SUSE:SLE-15:Update/go1.16  1.16.15
> - openSUSE:Factory/go1.16    1.16.15

Yes, the previous versions might be affected. Since those versions are past their support window for upstream and SUSE, no future maintenance releases will be available for go1.15 and go1.16. Will including the EOL packages on this issue allow the bug to be closed normally when the updates are published?
Comment 5 Hu 2022-07-14 07:53:43 UTC
Yes thanks, you are right, I will update the bugs.
Comment 7 Swamp Workflow Management 2022-08-04 16:16:48 UTC
SUSE-SU-2022:2671-1: An update that solves 10 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1190649,1201434,1201436,1201437,1201440,1201443,1201444,1201445,1201447,1201448,1202035
CVE References: CVE-2022-1705,CVE-2022-1962,CVE-2022-28131,CVE-2022-30630,CVE-2022-30631,CVE-2022-30632,CVE-2022-30633,CVE-2022-30635,CVE-2022-32148,CVE-2022-32189
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    go1.17-1.17.13-150000.1.42.1
openSUSE Leap 15.3 (src):    go1.17-1.17.13-150000.1.42.1
SUSE Manager Server 4.1 (src):    go1.17-1.17.13-150000.1.42.1
SUSE Manager Retail Branch Server 4.1 (src):    go1.17-1.17.13-150000.1.42.1
SUSE Manager Proxy 4.1 (src):    go1.17-1.17.13-150000.1.42.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    go1.17-1.17.13-150000.1.42.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    go1.17-1.17.13-150000.1.42.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    go1.17-1.17.13-150000.1.42.1
SUSE Linux Enterprise Module for Development Tools 15-SP4 (src):    go1.17-1.17.13-150000.1.42.1
SUSE Linux Enterprise Module for Development Tools 15-SP3 (src):    go1.17-1.17.13-150000.1.42.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    go1.17-1.17.13-150000.1.42.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    go1.17-1.17.13-150000.1.42.1
SUSE Enterprise Storage 7 (src):    go1.17-1.17.13-150000.1.42.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2022-08-04 16:19:08 UTC
SUSE-SU-2022:2672-1: An update that solves 10 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1193742,1201434,1201436,1201437,1201440,1201443,1201444,1201445,1201447,1201448,1202035
CVE References: CVE-2022-1705,CVE-2022-1962,CVE-2022-28131,CVE-2022-30630,CVE-2022-30631,CVE-2022-30632,CVE-2022-30633,CVE-2022-30635,CVE-2022-32148,CVE-2022-32189
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    go1.18-1.18.5-150000.1.25.1
openSUSE Leap 15.3 (src):    go1.18-1.18.5-150000.1.25.1
SUSE Linux Enterprise Module for Development Tools 15-SP4 (src):    go1.18-1.18.5-150000.1.25.1
SUSE Linux Enterprise Module for Development Tools 15-SP3 (src):    go1.18-1.18.5-150000.1.25.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.