Описание
Security update for go1.24
This update for go1.24 fixes the following issues:
- Update to go1.24.2
- CVE-2025-22871: Fix an issue with request smuggling through invalid chunked data. (bsc#1240550)
Список пакетов
Container bci/golang:latest
go1.24-1.24.2-150000.1.17.1
go1.24-doc-1.24.2-150000.1.17.1
go1.24-race-1.24.2-150000.1.17.1
SUSE Linux Enterprise Module for Development Tools 15 SP6
go1.24-1.24.2-150000.1.17.1
go1.24-doc-1.24.2-150000.1.17.1
go1.24-race-1.24.2-150000.1.17.1
openSUSE Leap 15.6
go1.24-1.24.2-150000.1.17.1
go1.24-doc-1.24.2-150000.1.17.1
go1.24-race-1.24.2-150000.1.17.1
Ссылки
- Link for SUSE-SU-2025:1153-1
- E-Mail link for SUSE-SU-2025:1153-1
- SUSE Security Ratings
- SUSE Bug 1236217
- SUSE Bug 1239182
- SUSE Bug 1240550
- SUSE CVE CVE-2025-22871 page
Описание
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
Затронутые продукты
Container bci/golang:latest:go1.24-1.24.2-150000.1.17.1
Container bci/golang:latest:go1.24-doc-1.24.2-150000.1.17.1
Container bci/golang:latest:go1.24-race-1.24.2-150000.1.17.1
SUSE Linux Enterprise Module for Development Tools 15 SP6:go1.24-1.24.2-150000.1.17.1
Ссылки
- CVE-2025-22871
- SUSE Bug 1240550