Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2024:3772-1 important: go1.22-openssl stack exhaustion

suse
Calendar Grey October 29, 2024
Dist Suse Esm H88
SUSE released an urgent security notice concerning go1.22-openssl patches, addressing numerous stack overflow vulnerabilities.
* bsc#1218424 * bsc#1219988 * bsc#1220999 * bsc#1221000 * bsc#1221001

Summary

## This update for go1.22-openssl fixes the following issues: This update ships go1.22-openssl 1.22.7.1 (jsc#SLE-18320) * Update to version 1.22.7.1 cut from the go1.22-fips-release branch at the revision tagged go1.22.7-1-openssl-fips. * Update to Go 1.22.7 (#229) * go1.22.7 (released 2024-09-05) includes security fixes to the encoding/gob, go/build/constraint, and go/parser packages, as well as bug fixes to the fix command and the runtime. CVE-2024-34155 CVE-2024-34156 CVE-2024-34158: \- go#69142 go#69138 bsc#1230252 security: fix CVE-2024-34155 go/parser: stack exhaustion in all Parse* functions (CVE-2024-34155) \- go#69144 go#69139 bsc#1230253 security: fix CVE-2024-34156 encoding/gob: stack exhaustion in Decoder.Decode (CVE-2024-34156) \- go#69148

References

* bsc#1218424

* bsc#1219988

* bsc#1220999

* bsc#1221000

* bsc#1221001

* bsc#1221002

* bsc#1221003

* bsc#1221400

* bsc#1224017

* bsc#1224018

* bsc#1225973

* bsc#1225974

* bsc#1227314

* bsc#1230252

* bsc#1230253

* bsc#1230254

* jsc#PED-1962

* jsc#SLE-18320

Cross-

* CVE-2023-45288

* CVE-2023-45289

* CVE-2023-45290

* CVE-2024-24783

* CVE-2024-24784

* CVE-2024-24785

* CVE-2024-24787

* CVE-2024-24788

* CVE-2024-24789

* CVE-2024-24790

* CVE-2024-24791

* CVE-2024-34155

* CVE-2024-34156

* CVE-2024-34158

CVSS scores:

* CVE-2023-45288 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-45289 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2023-45290 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:3772-1
Release Date: 2024-10-29T13:54:03Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here