Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8 MGASA-2021-0475 Critical: Golang Zip Panic Issues

mageia
Calendar Grey October 13, 2021
Dist Mageia Esm H88
Addressing Golang vulnerabilities in Mageia is crucial. Ensure that all packages are updated regularly to prevent panic and fatal exceptions in ZIP file processing.
The fix for CVE-2021-33196 can be bypassed by crafted inputs

Summary

The fix for CVE-2021-33196 can be bypassed by crafted inputs. As a result, the NewReader and OpenReader functions in archive/zip can still cause a panic or an unrecoverable fatal error when reading an archive that claims to contain a large number of files, regardless of its actual size. (CVE-2021-39293) A security issue has been found in go before version 1.17.2. When invoking functions from WASM modules, built using GOARCH=wasm GOOS=js, passing very large arguments can cause portions of the module to be overwritten with data from the arguments. (CVE-2021-38297)

References

- https://bugs.mageia.org/show_bug.cgi?id=29526

- https://groups.google.com/g/golang-announce/c/dx9d7IOseHw

- https://groups.google.com/g/golang-announce/c/7efr4VBoZIw

- https://groups.google.com/g/golang-announce/c/AEBu9j7yj5A

-

- https://security.archlinux.org/CVE-2021-38297

- https://www.cve.org/CVERecord?id=CVE-2021-39293

- https://www.cve.org/CVERecord?id=CVE-2021-38297

Resolution

SRPMS

- 8/core/golang-1.17.2-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0475.html
Type: security
CVE: CVE-2021-39293, CVE-2021-38297

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here