An update for butane is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: butane security, bug fix, and enhancement update Advisory ID: RHSA-2023:2193-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2193 Issue date: 2023-05-09 CVE Names: CVE-2022-27664 CVE-2022-32189 ==================================================================== 1. Summary: An update for butane is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: Butane translates human-readable Butane Configs into machine-readable Ignition configs for provisioning operating systems that use Ignition. The following packages have been upgraded to a later upstream version: butane (0.16.0). (BZ#2135475) Security Fix(es): * golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664) * golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: Fordetailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2113814 - CVE-2022-32189 golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service 2124669 - CVE-2022-27664 golang: net/http: handle server errors after sending GOAWAY 2135475 - Update butane to latest upstream version 0.16.0 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: butane-0.16.0-1.el9.src.rpm aarch64: butane-0.16.0-1.el9.aarch64.rpm butane-debuginfo-0.16.0-1.el9.aarch64.rpm butane-debugsource-0.16.0-1.el9.aarch64.rpm ppc64le: butane-0.16.0-1.el9.ppc64le.rpm butane-debuginfo-0.16.0-1.el9.ppc64le.rpm butane-debugsource-0.16.0-1.el9.ppc64le.rpm s390x: butane-0.16.0-1.el9.s390x.rpm butane-debuginfo-0.16.0-1.el9.s390x.rpm butane-debugsource-0.16.0-1.el9.s390x.rpm x86_64: butane-0.16.0-1.el9.x86_64.rpm butane-debuginfo-0.16.0-1.el9.x86_64.rpm butane-debugsource-0.16.0-1.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-27664 https://access.redhat.com/security/cve/CVE-2022-32189 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZFo0ptzjgjWX9erEAQge6A//ZpWXomxucsX7wvVE5yZHZHM95peYYg43 OsTi+2VbGn4sf6LxH/d3fXhnheMLT72aGJJfqH5LF8cURjT0GLV/WhNJeNx/G+G2 qa7N/hi2mjH/T3ot6aGgm0sX6JddLhvLLs9HhEoQeB7bN1JtCbgndvDuA56mOkew FrKuGPMcbzc3PPOkw0/2CHUMcx9lSM1FoeUyAZU9pEl8d0T3Zmwmioi2llQlJINW SvmfDb+YVMkIFnswpVbPz3SmDDHWy68HCGhCYcBy+yHSMJk4R+LpmV+wpnGwEor6 OrTlDb8GrSuLwnbPtAnkhOIG3TsjwBUH1XWxIMsn1HMXaQZofnJ/RzJ1irgmaoja LSzFVt51FmH/3FeX5r9X07Tw3pSn2Iu2jcxHBQHuoMMVMb3YnYf97ES7wqg2lAk+ 7DQ9TKGdRaGYFbuu5nE9ekZ634GUVXhXnLEKbprwGy2SE1OGNH5eeGGouEAyD7FX 00clOMbfElIrZzs9rOYd28TU3vAEFCcFS/WlN4Op9hogVFtb37kR6tvnfJjoMd6E a+5Or8UuyDr9ZStt2lQ7kem5TwxDxNrOdZ7vl/zfjCidYPqGs1XNkgg+tSzFOvsa 8OWLeMgehVGY0DvUBbcs07MQcTJ1CCdJYExQId6Z5RfQbE20/23x0GkvkMxttBEt flgUVYUXUFk=8Inq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs --- This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: - CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode - CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3969b64d4b 2022-07-17 00:57:11.020145 --------------------------------------------------------------------------------Name : butane Product : Fedora 35 Version : 0.15.0 Release : 2.fc35 URL : https://github.com/coreos/butane Summary : Butane config transpiler Description : Butane translates human-readable Butane Configs into machine-readable Ignition configs for provisioning operating systems that use Ignition. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs --- This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: - CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode -CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar -CVE-2022-29526 golang: syscall: faccessat checks wrong group (There are some Go CVEs that are a little bit older that will also be mitigated by the rebuild for packages that haven't been updated recently) CVEs in other golang libraries that affect a subset of Go packages: - CVE-2022-21698 golang-github-prometheus-client: prometheus/client_golang: Denial of service using InstrumentHandlerCounter - CVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled Key ---- Initial import for golang-github-a8m-envsubst Resolves: rhbz#2074406 ---- Initial package Resolves: rhbz#2074438 ----Update to v3.14.0 (close rhbz#2105612) ---- Fix merge ---- Update to 1.22.1 - Close: rhbz#2077577 --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #2074406 - Review Request: golang-github-a8m-envsubst - Environment variables substitution for Go https://bugzilla.redhat.com/show_bug.cgi?id=2074406 [ 2 ] Bug #2074438 - Review Request: golang-github-goccy-yaml - YAML support for the Go language https://bugzilla.redhat.com/show_bug.cgi?id=2074438 [ 3 ] Bug #2077577 - powerline-go-1.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2077577 [ 4 ] Bug #2105612 - golang-github-task-3.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2105612 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3969b64d4b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.