Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2023:1964-2 Critical: bci/golang Security Advisory

suse
Calendar Grey June 17, 2023
Dist Suse Esm H88
Routine security enhancement for bci/golang image tackling multiple urgent concerns and weaknesses.
The container bci/golang was updated

Summary

Advisory ID: SUSE-SU-2023:2526-1 Released: Fri Jun 16 17:33:35 2023 Summary: Security update for go1.20 Type: security Severity: moderate

References

References : 1206346 1212073 1212074 1212075 1212076 CVE-2023-29402 CVE-2023-29403

CVE-2023-29404 CVE-2023-29405

1206346,1212073,1212074,1212075,1212076,CVE-2023-29402,CVE-2023-29403,CVE-2023-29404,CVE-2023-29405

This update for go1.20 fixes the following issues:

Update to go1.20.5 (bsc#1206346):

- CVE-2023-29402: cmd/go: Fixed cgo code injection (bsc#1212073).

- CVE-2023-29403: runtime: Fixed unexpected behavior of setuid/setgid binaries (bsc#1212074).

- CVE-2023-29404: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212075).

- CVE-2023-29405: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212076). ...

Read the Full Advisory

Container Advisory ID : SUSE-CU-2023:1963-1
Container Tags : bci/golang:1.20 , bci/golang:1.20-3.5 , bci/golang:latest
Container Release : 3.5
Severity : moderate
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here