Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2024:3938-1 important: go1.22-openssl stack exhaustion fix

suse
Calendar Grey November 7, 2024
Dist Suse Esm H88
SUSE reveals crucial security enhancements for go1.22-openssl addressing several vulnerabilities. It is advised to apply the suggested updates.
* bsc#1218424 * bsc#1219988 * bsc#1220999 * bsc#1221000 * bsc#1221001

Summary

## This update for go1.22-openssl fixes the following issues: This update ships go1.22-openssl 1.22.7.1 (jsc#SLE-18320) * Update to version 1.22.7.1 cut from the go1.22-fips-release branch at the revision tagged go1.22.7-1-openssl-fips. * Update to Go 1.22.7 (#229) * go1.22.7 (released 2024-09-05) includes security fixes to the encoding/gob, go/build/constraint, and go/parser packages, as well as bug fixes to the fix command and the runtime. CVE-2024-34155 CVE-2024-34156 CVE-2024-34158: \- go#69142 go#69138 bsc#1230252 security: fix CVE-2024-34155 go/parser: stack exhaustion in all Parse* functions (CVE-2024-34155) \- go#69144 go#69139 bsc#1230253 security: fix CVE-2024-34156 encoding/gob: stack exhaustion in Decoder.Decode (CVE-2024-34156) \- go#69148

References

* bsc#1218424

* bsc#1219988

* bsc#1220999

* bsc#1221000

* bsc#1221001

* bsc#1221002

* bsc#1221003

* bsc#1221400

* bsc#1224017

* bsc#1224018

* bsc#1225973

* bsc#1225974

* bsc#1227314

* bsc#1230252

* bsc#1230253

* bsc#1230254

* jsc#PED-1962

* jsc#SLE-18320

Cross-

* CVE-2023-45288

* CVE-2023-45289

* CVE-2023-45290

* CVE-2024-24783

* CVE-2024-24784

* CVE-2024-24785

* CVE-2024-24787

* CVE-2024-24788

* CVE-2024-24789

* CVE-2024-24790

* CVE-2024-24791

* CVE-2024-34155

* CVE-2024-34156

* CVE-2024-34158

CVSS scores:

* CVE-2023-45288 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-45289 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2023-45289 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:3938-1
Release Date: 2024-11-07T10:08:24Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here