Oracle Linux Security Advisory ELSA-2024-6908

http://linux.oracle.com/errata/ELSA-2024-6908.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
delve-1.21.2-4.0.1.module+el8.10.0+90407+20770c94.x86_64.rpm
golang-1.21.13-2.module+el8.10.0+90407+20770c94.x86_64.rpm
golang-bin-1.21.13-2.module+el8.10.0+90407+20770c94.x86_64.rpm
golang-docs-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm
golang-misc-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm
golang-src-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm
golang-tests-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm
go-toolset-1.21.13-1.module+el8.10.0+90407+20770c94.x86_64.rpm

aarch64:
delve-1.21.2-4.0.1.module+el8.10.0+90407+20770c94.aarch64.rpm
golang-1.21.13-2.module+el8.10.0+90407+20770c94.aarch64.rpm
golang-bin-1.21.13-2.module+el8.10.0+90407+20770c94.aarch64.rpm
golang-docs-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm
golang-misc-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm
golang-src-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm
golang-tests-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm
go-toolset-1.21.13-1.module+el8.10.0+90407+20770c94.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//delve-1.21.2-4.0.1.module+el8.10.0+90407+20770c94.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates//golang-1.21.13-2.module+el8.10.0+90407+20770c94.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates//go-toolset-1.21.13-1.module+el8.10.0+90407+20770c94.src.rpm

Related CVEs:

CVE-2024-24791
CVE-2024-34155
CVE-2024-34156
CVE-2024-34158




Description of changes:

delve
[1.21.2-4.0.1]
- Disable DWARF compression which has issues (Alex Burmashev)

[1.21.2-4]
- Skip tests in %check due to incompatible Go version in buildroot (temporary).
- Resolves: RHEL-59518

golang
[1.21.13-2]
- Rebuild Go with CVE Fixes
- Remove fix-memleak-setupRSA.patch (exists upstream)
- Resolves: RHEL-58223
- Resolves: RHEL-57961
- Resolves: RHEL-57847
- Resolves: RHEL-57860

[1.21.13-1]
- Update to Go1.21.13 to fix CVE-2024-24791
- Resolves: RHEL-47198

go-toolset
[1.21.13-1]
- Fix CVE-2024-24791
- Resolves: RHEL-47198


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2024-6908: go-toolset:ol8 Important Security Advisory Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

delve [1.21.2-4.0.1] - Disable DWARF compression which has issues (Alex Burmashev) [1.21.2-4] - Skip tests in %check due to incompatible Go version in buildroot (temporary). - Resolves: RHEL-59518 golang [1.21.13-2] - Rebuild Go with CVE Fixes - Remove fix-memleak-setupRSA.patch (exists upstream) - Resolves: RHEL-58223 - Resolves: RHEL-57961 - Resolves: RHEL-57847 - Resolves: RHEL-57860 [1.21.13-1] - Update to Go1.21.13 to fix CVE-2024-24791 - Resolves: RHEL-47198 go-toolset [1.21.13-1] - Fix CVE-2024-24791 - Resolves: RHEL-47198

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates//delve-1.21.2-4.0.1.module+el8.10.0+90407+20770c94.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//golang-1.21.13-2.module+el8.10.0+90407+20770c94.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//go-toolset-1.21.13-1.module+el8.10.0+90407+20770c94.src.rpm

x86_64

delve-1.21.2-4.0.1.module+el8.10.0+90407+20770c94.x86_64.rpm golang-1.21.13-2.module+el8.10.0+90407+20770c94.x86_64.rpm golang-bin-1.21.13-2.module+el8.10.0+90407+20770c94.x86_64.rpm golang-docs-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm golang-misc-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm golang-src-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm golang-tests-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm go-toolset-1.21.13-1.module+el8.10.0+90407+20770c94.x86_64.rpm

aarch64

delve-1.21.2-4.0.1.module+el8.10.0+90407+20770c94.aarch64.rpm golang-1.21.13-2.module+el8.10.0+90407+20770c94.aarch64.rpm golang-bin-1.21.13-2.module+el8.10.0+90407+20770c94.aarch64.rpm golang-docs-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm golang-misc-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm golang-src-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm golang-tests-1.21.13-2.module+el8.10.0+90407+20770c94.noarch.rpm go-toolset-1.21.13-1.module+el8.10.0+90407+20770c94.aarch64.rpm

i386

Severity
Related CVEs: CVE-2024-24791 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158

Related News