Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 38 Critical Update: Golang Timeout Issue Fix for CVE-2023-39325

fedora
Calendar Grey January 19, 2024
Dist Fedora Esm H88
The latest Fedora 38 release enhances the security of the golang-github-facebook-time library, addressing vulnerabilities tied to CVE-2023-39325.
Security fix for CVE-2023-39325

Summary

Meta's Time libraries.

Update Information:

Security fix for CVE-2023-39325

Change Log

* Wed Jan 10 2024 Michel Lind - 0^20240110git1649917-1 - Allow setting custom API timeouts (PR#318) - Enforce we are building against golang.org/x/net >= 0.17.0 for CVE-2023-39325 - Use SPDX license identifier - Backfill correct release tags in the changelog * Wed Jan 10 2024 Oleg Obleukhov - 0-0.16.20240110gitd1456d1 - Rebuild latest to include Calnex changes such as sptp and --save * Fri Oct 6 2023 Oleg Obleukhov - 0-0.15.20231006git599359b - Rebuild latest * Wed Oct 4 2023 Oleg Obleukhov - 0-0.14.20231004gite5c45cf - Add sptp package build and rebase on new commit * Thu Jul 20 2023 Fedora Release Engineering - 0-0.13.20220615git8413c32 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

References


[ 1 ] Bug #2248294 - golang-github-facebook-time: golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2248294

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f99ecead66' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: golang-github-facebook-time
Product: Fedora 38
Version: 0^20240110git1649917
Release: 1.fc38
Summary: Meta's Time libraries

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here