Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Ubuntu 22.04 LTS USN-7111-1 moderate: multiple denial of service risks

ubuntu
Calendar Grey November 14, 2024
Scroller Ubuntu
Essential security patches for Go in Ubuntu address various denial-of-service vulnerabilities and enhance overall system protection.
Several security issues were fixed in Go.

Summary

Several security issues were fixed in Go.

Software Description:

- golang-1.17: Go programming language compiler - metapackage

Details:

Philippe Antoine discovered that Go incorrectly handled crafted HTTP/2

streams. An attacker could possibly use this issue to cause a denial of

service. (CVE-2022-41723)

Marten Seemann discovered that Go did not properly manage memory under

certain circumstances. An attacker could possibly use this issue to cause

a panic resulting in a denial of service. (CVE-2022-41724)

Ameya Darshan and Jakob Ackermann discovered that Go did not properly

validate the amount of memory and disk files ReadForm can consume. An

attacker could possibly use this issue to cause a panic resulting in a

denial of service. (CVE-2022-41725)

Jakob Ackermann discovered that Go incorrectly handled multipart

forms. An attacker could possibly use this issue to consume an excessive

amount of resources, resulting in a denial of service. (CVE-2023-24536)

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
   golang-1.17                     1.17.13-3ubuntu1.3
   golang-1.17-go                  1.17.13-3ubuntu1.3
   golang-1.17-src                 1.17.13-3ubuntu1.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7111-1

CVE-2022-41723, CVE-2022-41724, CVE-2022-41725, CVE-2023-24536,

CVE-2023-39323, CVE-2023-45288, CVE-2023-45290, CVE-2024-24783,

CVE-2024-24784, CVE-2024-24789, CVE-2024-24791, CVE-2024-34155,

CVE-2024-34156, CVE-2024-34158

Ubuntu Security Notice USN-7111-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.