Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 7081-1: Go Security Advisory Updates

ubuntu
Calendar Grey October 23, 2024
Scroller Ubuntu
Ubuntu Security Notice USN-7081-1 addresses critical Golang issues with denial of service risks on multiple Ubuntu releases.
Several security issues were fixed in Go.

Summary

Several security issues were fixed in Go.

Software Description:

- golang-1.22: Go programming language compiler

Details:

It was discovered that the Go net/http module did not properly handle

responses to requests with an "Expect: 100-continue" header under certain

circumstances. An attacker could possibly use this issue to cause a denial

of service. (CVE-2024-24791)

It was discovered that the Go parser module did not properly handle deeply

nested literal values. An attacker could possibly use this issue to cause

a panic resulting in a denial of service. (CVE-2024-34155)

It was discovered that the Go encoding/gob module did not properly handle

message decoding under certain circumstances. An attacker could possibly

use this issue to cause a panic resulting in a denial of service.

(CVE-2024-34156)

It was discovered that the Go build module did not properly handle certain

build tag lines with deeply nested expressions. An attacker could possibly

use this ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
   golang-1.22                     1.22.2-2ubuntu0.3
   golang-1.22-go                  1.22.2-2ubuntu0.3
   golang-1.22-src                 1.22.2-2ubuntu0.3

Ubuntu 22.04 LTS
   golang-1.22                     1.22.2-2~22.04.2
   golang-1.22-go                  1.22.2-2~22.04.2
   golang-1.22-src                 1.22.2-2~22.04.2

Ubuntu 20.04 LTS
   golang-1.22                     1.22.2-2~20.04.2
   golang-1.22-go                  1.22.2-2~20.04.2
   golang-1.22-src                 1.22.2-2~20.04.2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7081-1

CVE-2024-24791, CVE-2024-34155, CVE-2024-34156, CVE-2024-34158

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7081-1

Topics%20covered

Topics Covered

No topics assigned

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.