Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

openSUSE 15.5: SUSE-SU-2023:3263-1 important: Go1.19 RSA Key

opensuse
Calendar Grey August 10, 2023
Scroller Opensuse
Important Go 1.19 security patch addresses vulnerabilities such as limitations on RSA keys to strengthen overall system protection.
This update for go1.19 fixes the following issues: Update to go v1.19.12 (released 2023-08-01) (bsc#1200441) CVE-2023-29409: Restrict RSA keys in certificates to less than or equal...

Description

This update for go1.19 fixes the following issues:

* Update to go v1.19.12 (released 2023-08-01) (bsc#1200441)

* CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to

8192 bits to avoid DoSing client/server while validating signatures for

extremely large RSA keys. (bsc#1213880)

Patch

## Patch Instructions:

To install this SUSE Important update use the SUSE recommended installation

methods like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-3263=1

* Development Tools Module 15-SP4

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-3263=1

* Development Tools Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-3263=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3

zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-3263=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3

zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-3263=1

* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3

zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-3263=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP3

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-3263=1

* SUSE Enterprise Storage...

Read the Full Advisory

Package List

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* go1.19-1.19.12-150000.1.40.1

* go1.19-race-1.19.12-150000.1.40.1

* go1.19-doc-1.19.12-150000.1.40.1

* Development Tools Module 15-SP4 (aarch64 ppc64le s390x x86_64)

* go1.19-1.19.12-150000.1.40.1

* go1.19-doc-1.19.12-150000.1.40.1

* Development Tools Module 15-SP4 (aarch64 x86_64)

* go1.19-race-1.19.12-150000.1.40.1

* Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64)

* go1.19-1.19.12-150000.1.40.1

* go1.19-race-1.19.12-150000.1.40.1

* go1.19-doc-1.19.12-150000.1.40.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (aarch64

x86_64)

* go1.19-1.19.12-150000.1.40.1

* go1.19-race-1.19.12-150000.1.40.1

* go1.19-doc-1.19.12-150000.1.40.1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64

x86_64)

* go1.19-1.19.12-150000.1.40.1

* go1.19-race-1.19.12-150000.1.40.1

* go1.19-doc-1.19.12-150000.1.40.1

* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x

x86_64)

* go1.19-1.19.12-150000.1.40.1

*...

Read the Full Advisory

References

* #1200441

* #1213880

## References:

* https://www.suse.com/security/cve/CVE-2023-29409.html

* https://bugzilla.suse.com/show_bug.cgi?id=1200441

* https://bugzilla.suse.com/show_bug.cgi?id=1213880

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:3263-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.