Описание
Important: go-toolset:rhel8 security and bug fix update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.
Security Fix(es):
-
golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
-
golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)
-
golang: go/parser: stack exhaustion in all Parse* functions (CVE-2022-1962)
-
golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)
-
golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)
-
golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)
-
golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)
-
golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)
-
golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
-
Clean up dist-git patches (BZ#2110942)
-
Update Go to version 1.17.12 (BZ#2110943)
Затронутые продукты
Rocky Linux 8
Ссылки на источники
Исправления
- Red Hat - 2107342
- Red Hat - 2107371
- Red Hat - 2107374
- Red Hat - 2107376
- Red Hat - 2107383
- Red Hat - 2107386
- Red Hat - 2107388
- Red Hat - 2107390
- Red Hat - 2107392
Связанные уязвимости
Moderate: container-tools:rhel8 security, bug fix, and enhancement update
ELSA-2023-2758: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)
ELSA-2022-5799: go-toolset and golang security and bug fix update (IMPORTANT)
ELSA-2022-5775: go-toolset:ol8 security and bug fix update (IMPORTANT)