Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-3773

Опубликовано: 10 апр. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-3773: delve and golang security update (IMPORTANT)

delve [1.24.1-2.0.1]

  • Disable DWARF compression which has issues (Alex Burmashev)

[1.24.1-2]

  • Fix 3 test failures
  • Resolves: RHEL-83939
  • Resolves: RHEL-83958
  • Resolves: RHEL-7373

[1.24.1-1]

  • Rebase to Delve 1.24.1
  • Resolves: RHEL-64445

golang [1.23.6-2]

  • Fix runtime usleep issue on s390x (runtime-usleep-s390x.patch)
  • Resolves: RHEL-81242

[1.23.6-1]

  • Update to Go 1.23.6 (fips-1)
  • Resolves: RHEL-80344

[1.23.4-1]

  • Update to Go 1.23.4 (fips-1)
  • Resolves: RHEL-61048
  • Resolves: RHEL-61223

[1.23.2-1]

  • Rebase to Go1.23.2
  • Remove fix standard crypto panic patch as the source already has changes
  • Resolves: RHEL-62392

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

delve

1.24.1-2.0.1.el9_5

go-toolset

1.23.6-2.el9_5

golang

1.23.6-2.el9_5

golang-bin

1.23.6-2.el9_5

golang-docs

1.23.6-2.el9_5

golang-misc

1.23.6-2.el9_5

golang-race

1.23.6-2.el9_5

golang-src

1.23.6-2.el9_5

golang-tests

1.23.6-2.el9_5

Oracle Linux x86_64

delve

1.24.1-2.0.1.el9_5

go-toolset

1.23.6-2.el9_5

golang

1.23.6-2.el9_5

golang-bin

1.23.6-2.el9_5

golang-docs

1.23.6-2.el9_5

golang-misc

1.23.6-2.el9_5

golang-race

1.23.6-2.el9_5

golang-src

1.23.6-2.el9_5

golang-tests

1.23.6-2.el9_5

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
redhat
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
nvd
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
debian
10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested struc ...

rocky
8 месяцев назад

Important: skopeo security update