Oracle Linux Security Advisory ELSA-2024-4237

http://linux.oracle.com/errata/ELSA-2024-4237.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
delve-1.21.2-3.0.1.module+el8.10.0+90307+cdf2b281.x86_64.rpm
golang-1.21.11-1.module+el8.10.0+90357+32bea22c.x86_64.rpm
golang-bin-1.21.11-1.module+el8.10.0+90357+32bea22c.x86_64.rpm
golang-docs-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm
golang-misc-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm
golang-src-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm
golang-tests-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm
go-toolset-1.21.11-1.module+el8.10.0+90357+32bea22c.x86_64.rpm

aarch64:
delve-1.21.2-3.0.1.module+el8.10.0+90307+cdf2b281.aarch64.rpm
golang-1.21.11-1.module+el8.10.0+90357+32bea22c.aarch64.rpm
golang-bin-1.21.11-1.module+el8.10.0+90357+32bea22c.aarch64.rpm
golang-docs-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm
golang-misc-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm
golang-src-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm
golang-tests-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm
go-toolset-1.21.11-1.module+el8.10.0+90357+32bea22c.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//delve-1.21.2-3.0.1.module+el8.10.0+90307+cdf2b281.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates//golang-1.21.11-1.module+el8.10.0+90357+32bea22c.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates//go-toolset-1.21.11-1.module+el8.10.0+90357+32bea22c.src.rpm

Related CVEs:

CVE-2024-24789
CVE-2024-24790




Description of changes:

delve
[1.21.2-3.0.1]
- Disable DWARF compression which has issues (Alex Burmashev)

[1.21.2-3]
- Skip an additional test as it's breaking in the CI system.
- Modify the name of the patch.
- Resolves: RHEL-22820

[1.21.2-2]
- Fix: Remove architectures from exclude ExcludeArch
- Resolves: RHEL-22820

[1.21.2-1]
- Rebase to 1.21.2
- Add support for ppc64le and aarch64
- Enable the test suite
- Modify ports: Some CI systems complain about the usage of the 8888 port.
- Improve the way PPC64LE support is enabled.
- Resolves: RHEL-22820

golang
[1.21.11-1]
- Update to Go1.21.11 to address CVE-2024-24789 and CVE-2024-24790
- Resolves: RHEL-40274

[1.21.10]
- Update to Go 1.21.10
- Resolves: RHEL-36993

go-toolset
[1.21.11-1]
- Rebase to Go1.21.11 that includes fixes for CVE-2024-24789 and CVE-2024-24790
- Resolves: RHEL-40274

[1.21.10-1]
- Update to Go 1.21.10
- Resolves: RHEL-36993


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2024-4237: go-toolset Moderate Security Advisory Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

delve [1.21.2-3.0.1] - Disable DWARF compression which has issues (Alex Burmashev) [1.21.2-3] - Skip an additional test as it's breaking in the CI system. - Modify the name of the patch. - Resolves: RHEL-22820 [1.21.2-2] - Fix: Remove architectures from exclude ExcludeArch - Resolves: RHEL-22820 [1.21.2-1] - Rebase to 1.21.2 - Add support for ppc64le and aarch64 - Enable the test suite - Modify ports: Some CI systems complain about the usage of the 8888 port. - Improve the way PPC64LE support is enabled. - Resolves: RHEL-22820 golang [1.21.11-1] - Update to Go1.21.11 to address CVE-2024-24789 and CVE-2024-24790 - Resolves: RHEL-40274 [1.21.10] - Update to Go 1.21.10 - Resolves: RHEL-36993 go-toolset [1.21.11-1] - Rebase to Go1.21.11 that includes fixes for CVE-2024-24789 and CVE-2024-24790 - Resolves: RHEL-40274 [1.21.10-1] - Update to Go 1.21.10 - Resolves: RHEL-36993

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates//delve-1.21.2-3.0.1.module+el8.10.0+90307+cdf2b281.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//golang-1.21.11-1.module+el8.10.0+90357+32bea22c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//go-toolset-1.21.11-1.module+el8.10.0+90357+32bea22c.src.rpm

x86_64

delve-1.21.2-3.0.1.module+el8.10.0+90307+cdf2b281.x86_64.rpm golang-1.21.11-1.module+el8.10.0+90357+32bea22c.x86_64.rpm golang-bin-1.21.11-1.module+el8.10.0+90357+32bea22c.x86_64.rpm golang-docs-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm golang-misc-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm golang-src-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm golang-tests-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm go-toolset-1.21.11-1.module+el8.10.0+90357+32bea22c.x86_64.rpm

aarch64

delve-1.21.2-3.0.1.module+el8.10.0+90307+cdf2b281.aarch64.rpm golang-1.21.11-1.module+el8.10.0+90357+32bea22c.aarch64.rpm golang-bin-1.21.11-1.module+el8.10.0+90357+32bea22c.aarch64.rpm golang-docs-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm golang-misc-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm golang-src-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm golang-tests-1.21.11-1.module+el8.10.0+90357+32bea22c.noarch.rpm go-toolset-1.21.11-1.module+el8.10.0+90357+32bea22c.aarch64.rpm

i386

Severity
Related CVEs: CVE-2024-24789 CVE-2024-24790

Related News