Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:1153-1

Опубликовано: 07 апр. 2025
Источник: suse-cvrf

Описание

Security update for go1.24

This update for go1.24 fixes the following issues:

  • Update to go1.24.2
  • CVE-2025-22871: Fix an issue with request smuggling through invalid chunked data. (bsc#1240550)

Список пакетов

Container bci/golang:latest
go1.24-1.24.2-150000.1.17.1
go1.24-doc-1.24.2-150000.1.17.1
go1.24-race-1.24.2-150000.1.17.1
SUSE Linux Enterprise Module for Development Tools 15 SP6
go1.24-1.24.2-150000.1.17.1
go1.24-doc-1.24.2-150000.1.17.1
go1.24-race-1.24.2-150000.1.17.1
openSUSE Leap 15.6
go1.24-1.24.2-150000.1.17.1
go1.24-doc-1.24.2-150000.1.17.1
go1.24-race-1.24.2-150000.1.17.1

Описание

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.


Затронутые продукты
Container bci/golang:latest:go1.24-1.24.2-150000.1.17.1
Container bci/golang:latest:go1.24-doc-1.24.2-150000.1.17.1
Container bci/golang:latest:go1.24-race-1.24.2-150000.1.17.1
SUSE Linux Enterprise Module for Development Tools 15 SP6:go1.24-1.24.2-150000.1.17.1

Ссылки