Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

Mageia 8 MGASA-2022-0171 Critical: Golang Stack Overflow

mageia
Calendar Grey May 12, 2022
Dist Mageia Esm H88
Golang libraries revised to mitigate security risks in Mageia. Resolution for stack overflow issues in Decode and issues with large scalars.
encoding/pem: fix stack overflow in Decode

Summary

encoding/pem: fix stack overflow in Decode. A large (more than 5 MB) PEM input can cause a stack overflow in Decode, leading the program to crash (CVE-2022-24675)
crypto/elliptic: tolerate all oversized scalars in generic P-256. A crafted scalar input longer than 32 bytes can cause P256().ScalarMult or P256().ScalarBaseMult to panic. Indirect uses through crypto/ecdsa and crypto/tls are unaffected. amd64, arm64, ppc64le, and s390x are unaffected. (CVE-2022-28327)

References

- https://bugs.mageia.org/show_bug.cgi?id=30362

-

- https://www.cve.org/CVERecord?id=CVE-2022-24675

- https://www.cve.org/CVERecord?id=CVE-2022-28327

Resolution

SRPMS

- 8/core/golang-1.17.9-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 May 2022
URL: https://advisories.mageia.org/MGASA-2022-0171.html
Type: security
CVE: CVE-2022-24675, CVE-2022-28327

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here