Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2023:674-1 Important: Bci/Golang Container Security Update

suse
Calendar Grey March 16, 2023
Dist Suse Esm H88
SUSE enhances bci/python container with vital fixes tackling several security vulnerabilities and optimizing performance.
The container bci/golang was updated

Summary

Advisory ID: SUSE-SU-2023:733-1 Released: Tue Mar 14 18:07:08 2023 Summary: Security update for go1.19 Type: security Severity: important

References

References : 1200441 1208269 1208270 1208271 1208272 1209030 CVE-2022-41722

CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-24532

1200441,1208269,1208270,1208271,1208272,1209030,CVE-2022-41722,CVE-2022-41723,CVE-2022-41724,CVE-2022-41725,CVE-2023-24532

This update for go1.19 fixes the following issues:

- CVE-2022-41722: Fixed path traversal in filepath.Clean on Windows (bsc#1208269).

- CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270).

- CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271).

- CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272).

- CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1209030).

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:674-1
Container Tags : bci/golang:1.19 , bci/golang:1.19-20.33 , bci/golang:latest
Container Release : 20.33
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here