CVE-2021-38297

CRITICAL

Go <1.16.9, <1.17.2 - Buffer Overflow

Title source: llm

Description

Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.

Exploits (2)

nomisec WORKING POC 6 stars
by gkrishnan724 · poc
https://github.com/gkrishnan724/CVE-2021-38297
nomisec WORKING POC
by paras98 · poc
https://github.com/paras98/CVE-2021-38297-Go-wasm-Replication

Scores

CVSS v3 9.8
EPSS 0.1063
EPSS Percentile 93.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (3)
fedoraproject/fedora 34
fedoraproject/fedora 35
golang/go < 1.16.9
Published Oct 18, 2021
Tracked Since Feb 18, 2026