CVE-2021-29923
published 2021-08-07CVE-2021-29923: Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
3.77%
88.7th percentile
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-1.15 | — | — |
| fedoraproject | fedora | — | — |
| golang | go | < 1.17 | 1.17 |
| msrc | azl3_golang_1.24.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.11.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.16.2-2_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_golang_1.16.7-1_on_cbl_mariner_1.0 | — | — |
| oracle | timesten_in-memory_database | < 21.1.1.1.0 | 21.1.1.1.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle TimesTen In-Memory Database Risk Matrix: EM TimesTen plug-in (Go) — CVE-2021-29923
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-29923 [HIGH] Oracle Oracle TimesTen In-Memory Database Risk Matrix: EM TimesTen plug-in (Go) — CVE-2021-29923
Oracle Oracle TimesTen In-Memory Database Risk Matrix: EM TimesTen plug-in (Go) vulnerability
CVE: CVE-2021-29923
CVSS: 7.5
Protocol: TCP/IP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Microsoft
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet which (in some situations) allows attackers to bypass access control that is based on IP ad
vendor_msrc·2021-08-10·CVSS 7.5
CVE-2021-29923 [HIGH] Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet which (in some situations) allows attackers to bypass access control that is based on IP ad
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet which (in some situations) allows attackers to bypass access control that is based on IP addresses because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blo
Red Hat
golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet
vendor_redhat·2021-03-22·CVSS 7.5
CVE-2021-29923 [HIGH] CWE-20 golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet
golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
A flaw was found in golang. Extraneous zero characters at the beginning of an IP address octet are not properly considered which could allow an attacker to bypass IP-based access controls. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: This vulnerability potentially affects any component written in Go that uses the n
Debian
CVE-2021-29923: golang-1.15 - Go before 1.17 does not properly consider extraneous zero characters at the begi...
vendor_debian·2021·CVSS 7.5
CVE-2021-29923 [HIGH] CVE-2021-29923: golang-1.15 - Go before 1.17 does not properly consider extraneous zero characters at the begi...
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
Scope: local
bullseye: open
GHSA
GHSA-38h6-vxp4-qxvm: Go before 1
ghsa_unreviewed·2022-05-24
CVE-2021-29923 [HIGH] GHSA-38h6-vxp4-qxvm: Go before 1
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
OSV
CVE-2021-29923: Go before 1
osv·2021-08-07·CVSS 7.5
CVE-2021-29923 [HIGH] CVE-2021-29923: Go before 1
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudishttps://github.com/golang/go/issues/30999https://github.com/golang/go/issues/43389https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-016.mdhttps://go-review.googlesource.com/c/go/+/325829/https://golang.org/pkg/net/#ParseCIDRhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4CHKSFMHZVOBCZSSVRE3UEYNKARTBMTM/https://security.gentoo.org/glsa/202208-02https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://defcon.org/html/defcon-29/dc-29-speakers.html#kaoudishttps://github.com/golang/go/issues/30999https://github.com/golang/go/issues/43389https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-016.mdhttps://go-review.googlesource.com/c/go/+/325829/https://golang.org/pkg/net/#ParseCIDRhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4CHKSFMHZVOBCZSSVRE3UEYNKARTBMTM/https://security.gentoo.org/glsa/202208-02https://www.oracle.com/security-alerts/cpujan2022.html
2021-08-07
Published