Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

openSUSE Leap 15.4, 15.5: SUSE-SU-2023:4469-1 moderate: go1.21-openssl fix

opensuse
Calendar Grey November 16, 2023
Scroller Opensuse
The recent release of go1.21-openssl resolves various concerns and introduces upgrades for development utilities on openSUSE.
This update for go1.21-openssl fixes the following issues: Update to version 1.21.4.1 cut from the go1.21-openssl-fips branch at the revision tagged go1.21.4-1-openssl-fips.

Description

This update for go1.21-openssl fixes the following issues:

Update to version 1.21.4.1 cut from the go1.21-openssl-fips branch at the

revision tagged go1.21.4-1-openssl-fips.

* Update to go1.21.4

go1.21.4 (released 2023-11-07) includes security fixes to the path/filepath

package, as well as bug fixes to the linker, the runtime, the compiler, and the

go/types, net/http, and runtime/cgo packages.

* security: fix CVE-2023-45283 CVE-2023-45284 path/filepath: insecure parsing

of Windows paths (bsc#1216943, bsc#1216944)

* spec: update unification rules

* cmd/compile: internal compiler error: expected struct value to have type

struct

* cmd/link: split text sections for arm 32-bit

* runtime: MADV_COLLAPSE causes production performance issues on Linux

* go/types, x/tools/go/ssa: panic: type param without replacement encountered

* cmd/compile: -buildmode=c-archive produces code not suitable for use in a

shared object on arm64

* net/http: http2 page fails on firefox/safari if...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-4469=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-4469=1

* Development Tools Module 15-SP4

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-4469=1

* Development Tools Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-4469=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* go1.21-openssl-doc-1.21.4.1-150000.1.5.1

* go1.21-openssl-race-1.21.4.1-150000.1.5.1

* go1.21-openssl-1.21.4.1-150000.1.5.1

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* go1.21-openssl-doc-1.21.4.1-150000.1.5.1

* go1.21-openssl-race-1.21.4.1-150000.1.5.1

* go1.21-openssl-1.21.4.1-150000.1.5.1

* Development Tools Module 15-SP4 (aarch64 ppc64le s390x x86_64)

* go1.21-openssl-doc-1.21.4.1-150000.1.5.1

* go1.21-openssl-race-1.21.4.1-150000.1.5.1

* go1.21-openssl-1.21.4.1-150000.1.5.1

* Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64)

* go1.21-openssl-doc-1.21.4.1-150000.1.5.1

* go1.21-openssl-race-1.21.4.1-150000.1.5.1

* go1.21-openssl-1.21.4.1-150000.1.5.1

References

* bsc#1212475

* bsc#1212667

* bsc#1212669

* bsc#1215084

* bsc#1215085

* bsc#1215086

* bsc#1215087

* bsc#1215090

* bsc#1215985

* bsc#1216109

* bsc#1216943

* bsc#1216944

* jsc#SLE-18320

## References:

* https://www.suse.com/security/cve/CVE-2023-39318.html

* https://www.suse.com/security/cve/CVE-2023-39319.html

* https://www.suse.com/security/cve/CVE-2023-39320.html

* https://www.suse.com/security/cve/CVE-2023-39321.html

* https://www.suse.com/security/cve/CVE-2023-39322.html

* https://www.suse.com/security/cve/CVE-2023-39323.html

* https://www.suse.com/security/cve/CVE-2023-39325.html

* https://www.suse.com/security/cve/CVE-2023-44487.html

* https://www.suse.com/security/cve/CVE-2023-45283.html

* https://www.suse.com/security/cve/CVE-2023-45284.html

* https://bugzilla.suse.com/show_bug.cgi?id=1212475

* https://bugzilla.suse.com/show_bug.cgi?id=1212667

* https://bugzilla.suse.com/show_bug.cgi?id=1212669

* https://bugzilla.suse.com/show_bug.cgi?id=1215084

* https://bugzilla.suse.com/show_bug.cgi?id=1215085

*...

Read the Full Advisory

Announcement ID: SUSE-SU-2023:4469-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.