Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:7950

Опубликовано: 15 нояб. 2022
Источник: rocky
Оценка: Low

Описание

Low: Image Builder security, bug fix, and enhancement update

Image Builder is a service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood.

Security Fix(es):

  • golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
cockpit-composernoarch1.el9cockpit-composer-41-1.el9.noarch.rpm
weldr-clientx86_644.el9weldr-client-35.5-4.el9.x86_64.rpm
osbuildnoarch1.el9.rocky.0.1osbuild-65-1.el9.rocky.0.1.noarch.rpm
osbuild-luks2noarch1.el9.rocky.0.1osbuild-luks2-65-1.el9.rocky.0.1.noarch.rpm
osbuild-lvm2noarch1.el9.rocky.0.1osbuild-lvm2-65-1.el9.rocky.0.1.noarch.rpm
osbuild-ostreenoarch1.el9.rocky.0.1osbuild-ostree-65-1.el9.rocky.0.1.noarch.rpm
osbuild-selinuxnoarch1.el9.rocky.0.1osbuild-selinux-65-1.el9.rocky.0.1.noarch.rpm
python3-osbuildnoarch1.el9.rocky.0.1python3-osbuild-65-1.el9.rocky.0.1.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.

CVSS3: 6.5
redhat
почти 3 года назад

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.

CVSS3: 7.5
nvd
почти 3 года назад

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.

CVSS3: 7.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 3 года назад

A too-short encoded message can cause a panic in Float.GobDecode and R ...