Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian Stretch: DLA-2986-1 Critical: Golang-1.8 DoS Issues

debian lts
Calendar Grey April 28, 2022
Dist Debian Esm H88
Ubuntu Security Notice USN-4414-1 addresses weaknesses in libxml2 and urges users to update for improved safety.
Several vulnerabilities were discovered in the Go programming language

Summary

CVE-2022-23772

Rat.SetString in math/big has an overflow that can lead to
Uncontrolled Memory Consumption.

CVE-2022-23806

Curve.IsOnCurve in crypto/elliptic can incorrectly return true in
situations with a big.Int value that is not a valid field element.

CVE-2022-24921

regexp.Compile allows stack exhaustion via a deeply nested
expression.

For Debian 9 stretch, these problems have been fixed in version
1.8.1-1+deb9u5.

We recommend that you upgrade your golang-1.8 packages.

For the detailed security status of golang-1.8 please refer to
its security tracker page at:

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: golang-1.8
Version: 1.8.1-1+deb9u5
CVE ID: CVE-2022-23772 CVE-2022-23806 CVE-2022-24921

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here