Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-13940

Опубликовано: 18 авг. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-13940: go-toolset:rhel8 security update (IMPORTANT)

delve [1.24.1-1.0.1]

  • Disable DWARF compression which has issues (Alex Burmashev)

golang [1.24.6-1]

  • Update to Go 1.24.6 (fips-1)
  • Resolves: RHEL-106455

go-toolset [1.24.6-1]

  • Update to Go 1.24.6 (fips-1)
  • Resolves: RHEL-106455

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module go-toolset:ol8 is enabled

delve

1.24.1-1.0.1.module+el8.10.0+90602+3daf471e

go-toolset

1.24.6-1.module+el8.10.0+90641+f7c45302

golang

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-bin

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-docs

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-misc

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-src

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-tests

1.24.6-1.module+el8.10.0+90641+f7c45302

Oracle Linux x86_64

Module go-toolset:ol8 is enabled

delve

1.24.1-1.0.1.module+el8.10.0+90602+3daf471e

go-toolset

1.24.6-1.module+el8.10.0+90641+f7c45302

golang

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-bin

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-docs

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-misc

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-src

1.24.6-1.module+el8.10.0+90641+f7c45302

golang-tests

1.24.6-1.module+el8.10.0+90641+f7c45302

Связанные CVE

Связанные уязвимости

CVSS3: 8.6
ubuntu
24 дня назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
redhat
25 дней назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
nvd
24 дня назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
debian
24 дня назад

The go command may execute unexpected commands when operating in untru ...

suse-cvrf
около 1 месяца назад

Security update for go1.23