Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 39 FEDORA-2024-B85B97C0E9 Critical: DoS in Golang-X-Text

fedora
Calendar Grey January 18, 2024
Dist Fedora Esm H88
Fedora 39 has rolled out enhancements for golang-x-text, focusing on essential security vulnerabilities and boosting performance attributes.
update to v0.14.0, address CVE-2023-39325

Summary

Text is a repository of text-related packages related to internationalization

(i18n) and localization (l10n), such as character encodings, text

transformations, and locale-specific text handling.

Update Information:

update to v0.14.0, address CVE-2023-39325

Change Log

* Mon Nov 20 2023 Mark E. Fuller - 0.14.0-1 - update to v0.14.0, close rhbz#2248051 * Mon Sep 4 2023 Mark E. Fuller - 0.13.0-1 - update to v0.13.0, close rhbz#2237073 * Sat Aug 12 2023 Mark E. Fuller - 0.12.0-1 - v0.12.0, close rhbz#2214528

References


[ 1 ] Bug #2161274 - CVE-2022-41717 golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests https://bugzilla.redhat.com/show_bug.cgi?id=2161274 [ 2 ] Bug #2248209 - golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) https://bugzilla.redhat.com/show_bug.cgi?id=2248209

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b85b97c0e9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: golang-x-text
Product: Fedora 39
Version: 0.14.0
Release: 1.fc39
Summary: Go text processing support

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here