Описание
Security update for go1.16
This update for go1.16 fixes the following issues:
Update to go1.16.9
- CVE-2021-38297: misc/wasm, cmd/link: do not let command line args overwrite global data (bsc#1191468)
Список пакетов
openSUSE Leap 15.3
go1.16-1.16.9-1.29.1
go1.16-doc-1.16.9-1.29.1
go1.16-race-1.16.9-1.29.1
Ссылки
- E-Mail link for openSUSE-SU-2021:3487-1
- SUSE Security Ratings
- SUSE Bug 1182345
- SUSE Bug 1191468
- SUSE CVE CVE-2021-38297 page
Описание
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
Затронутые продукты
openSUSE Leap 15.3:go1.16-1.16.9-1.29.1
openSUSE Leap 15.3:go1.16-doc-1.16.9-1.29.1
openSUSE Leap 15.3:go1.16-race-1.16.9-1.29.1
Ссылки
- CVE-2021-38297
- SUSE Bug 1191468
- SUSE Bug 1206559
- SUSE Bug 1208723