An update that solves one vulnerability and has two fixes is now available. . SUSE Security Update: Security update for go1.17 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1167-1 Rating: important References: #1183043 #1190649 #1196732 Cross-References: CVE-2022-24921 CVSS scores: CVE-2022-24921 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-24921 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Development Tools 15-SP3 SUSE Linux Enterprise Module for Development Tools 15-SP4 SUSE Linux Enterprise Realtime Extension 15-SP2 SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap15.4 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for go1.17 fixes the following issues: Update to version 1.17.8 (bsc#1190649): - CVE-2022-24921: Fixed a potential denial of service via large regular expressions (bsc#1196732). Non-security fixes: - Fixed an issue with v2 modules (go#51332). - Fixed an issue when building source in riscv64 (go#51199). - Increased compatibility for the DNS protocol in the net module (go#51162). - Fixed an issue with histograms in the runtime/metrics module (go#50734). - Fixed an issue when parsing x509 certificates (go#51000). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1167=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1167=1 - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-1167=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-1167=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-1167=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-1167=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-1167=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-1167=1 - SUSE Linux Enterprise Realtime Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-RT-15-SP2-2022-1167=1 - SUSE Linux Enterprise Module for DevelopmentTools 15-SP4: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2022-1167=1 - SUSE Linux Enterprise Module for Development Tools 15-SP3: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP3-2022-1167=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-1167=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-1167=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-1167=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 - openSUSE Leap 15.4 (aarch64 x86_64): go1.17-race-1.17.8-150000.1.25.1 - openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 - openSUSE Leap 15.3 (aarch64 x86_64): go1.17-race-1.17.8-150000.1.25.1 - SUSE Manager Server 4.1 (ppc64le s390x x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 - SUSE Manager Server 4.1 (x86_64): go1.17-race-1.17.8-150000.1.25.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 go1.17-race-1.17.8-150000.1.25.1 - SUSE Manager Proxy 4.1 (x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 go1.17-race-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (x86_64): go1.17-race-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 x86_64): go1.17-race-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 go1.17-race-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Realtime Extension 15-SP2 (x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 go1.17-race-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Module for Development Tools 15-SP4 (aarch64 ppc64le s390x x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Module for Development Tools 15-SP4 (aarch64 x86_64): go1.17-race-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (aarch64 ppc64le s390x x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (aarch64 x86_64): go1.17-race-1.17.8-150000.1.25.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 go1.17-race-1.17.8-150000.1.25.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 go1.17-race-1.17.8-150000.1.25.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): go1.17-1.17.8-150000.1.25.1 go1.17-doc-1.17.8-150000.1.25.1 go1.17-race-1.17.8-150000.1.25.1 References: https://www.suse.com/security/cve/CVE-2022-24921.html https://bugzilla.suse.com/1183043 https://bugzilla.suse.com/1190649 https://bugzilla.suse.com/1196732 . SUSE Security Advisory: A critical enhancement for go1.17 tackles a significant denial of service vulnerability along with necessary repairs.. SUSE Update, Go1.17, Denial Of Service, Software Update, Security Fix. . Severity: Important. LinuxSecurity.com Team
An update for go-toolset-1.11 and go-toolset-1.11-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: go-toolset-1.11 and go-toolset-1.11-golang security update Advisory ID: RHSA-2019:2682-01 Product: Red Hat Developer Tools Advisory URL: https://access.redhat.com/errata/RHSA-2019:2682 Issue date: 2019-09-09 CVE Names: CVE-2019-9512 CVE-2019-9514 ==================================================================== 1. Summary: An update for go-toolset-1.11 and go-toolset-1.11-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): * HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512) * HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1735645 - CVE-2019-9512 HTTP/2: flood using PING frames results in unbounded memory growth 1735744 - CVE-2019-9514 HTTP/2: flood using HEADERS frames results in unbounded memory growth 6. Package List: Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7): Source: go-toolset-1.11-1.11.13-1.el7.src.rpm go-toolset-1.11-golang-1.11.13-2.el7.src.rpm aarch64: go-toolset-1.11-1.11.13-1.el7.aarch64.rpm go-toolset-1.11-build-1.11.13-1.el7.aarch64.rpm go-toolset-1.11-golang-1.11.13-2.el7.aarch64.rpm go-toolset-1.11-golang-bin-1.11.13-2.el7.aarch64.rpm go-toolset-1.11-golang-misc-1.11.13-2.el7.aarch64.rpm go-toolset-1.11-golang-src-1.11.13-2.el7.aarch64.rpm go-toolset-1.11-golang-tests-1.11.13-2.el7.aarch64.rpm go-toolset-1.11-runtime-1.11.13-1.el7.aarch64.rpm go-toolset-1.11-scldevel-1.11.13-1.el7.aarch64.rpm noarch: go-toolset-1.11-golang-docs-1.11.13-2.el7.noarch.rpm ppc64le: go-toolset-1.11-1.11.13-1.el7.ppc64le.rpm go-toolset-1.11-build-1.11.13-1.el7.ppc64le.rpm go-toolset-1.11-golang-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-golang-bin-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-golang-misc-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-golang-src-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-golang-tests-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-runtime-1.11.13-1.el7.ppc64le.rpm go-toolset-1.11-scldevel-1.11.13-1.el7.ppc64le.rpm s390x: go-toolset-1.11-1.11.13-1.el7.s390x.rpm go-toolset-1.11-build-1.11.13-1.el7.s390x.rpm go-toolset-1.11-golang-1.11.13-2.el7.s390x.rpm go-toolset-1.11-golang-bin-1.11.13-2.el7.s390x.rpm go-toolset-1.11-golang-misc-1.11.13-2.el7.s390x.rpm go-toolset-1.11-golang-src-1.11.13-2.el7.s390x.rpm go-toolset-1.11-golang-tests-1.11.13-2.el7.s390x.rpm go-toolset-1.11-runtime-1.11.13-1.el7.s390x.rpm go-toolset-1.11-scldevel-1.11.13-1.el7.s390x.rpm Red Hat Developer Tools for Red Hat Enterprise Linux Server (v.7): Source: go-toolset-1.11-1.11.13-1.el7.src.rpm go-toolset-1.11-golang-1.11.13-2.el7.src.rpm noarch: go-toolset-1.11-golang-docs-1.11.13-2.el7.noarch.rpm ppc64le: go-toolset-1.11-1.11.13-1.el7.ppc64le.rpm go-toolset-1.11-build-1.11.13-1.el7.ppc64le.rpm go-toolset-1.11-golang-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-golang-bin-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-golang-misc-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-golang-src-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-golang-tests-1.11.13-2.el7.ppc64le.rpm go-toolset-1.11-runtime-1.11.13-1.el7.ppc64le.rpm go-toolset-1.11-scldevel-1.11.13-1.el7.ppc64le.rpm s390x: go-toolset-1.11-1.11.13-1.el7.s390x.rpm go-toolset-1.11-build-1.11.13-1.el7.s390x.rpm go-toolset-1.11-golang-1.11.13-2.el7.s390x.rpm go-toolset-1.11-golang-bin-1.11.13-2.el7.s390x.rpm go-toolset-1.11-golang-misc-1.11.13-2.el7.s390x.rpm go-toolset-1.11-golang-src-1.11.13-2.el7.s390x.rpm go-toolset-1.11-golang-tests-1.11.13-2.el7.s390x.rpm go-toolset-1.11-runtime-1.11.13-1.el7.s390x.rpm go-toolset-1.11-scldevel-1.11.13-1.el7.s390x.rpm x86_64: go-toolset-1.11-1.11.13-1.el7.x86_64.rpm go-toolset-1.11-build-1.11.13-1.el7.x86_64.rpm go-toolset-1.11-golang-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-bin-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-misc-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-race-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-src-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-tests-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-runtime-1.11.13-1.el7.x86_64.rpm go-toolset-1.11-scldevel-1.11.13-1.el7.x86_64.rpm Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v.7): Source: go-toolset-1.11-1.11.13-1.el7.src.rpm go-toolset-1.11-golang-1.11.13-2.el7.src.rpm noarch: go-toolset-1.11-golang-docs-1.11.13-2.el7.noarch.rpm x86_64: go-toolset-1.11-1.11.13-1.el7.x86_64.rpm go-toolset-1.11-build-1.11.13-1.el7.x86_64.rpm go-toolset-1.11-golang-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-bin-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-misc-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-race-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-src-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-golang-tests-1.11.13-2.el7.x86_64.rpm go-toolset-1.11-runtime-1.11.13-1.el7.x86_64.rpm go-toolset-1.11-scldevel-1.11.13-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-9512 https://access.redhat.com/security/cve/CVE-2019-9514 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXXYgFNzjgjWX9erEAQjAEw//d2v+3X3macsmJgZk38NoHYBM8RM+HBWy EAmC+soQw0qKBqjo2rS+u2g7wiIGM21Wq6qvynYeHMV45R6MnObUH34DSWOBjuio D3I+9Q0KM6PEOoLmsyxj4Zhz0VzoseYVmbg84PiJKvRmyQb8fbr+i5gROEGwthKb V+9v292OTCp2szalLfQX6S+Kmgf6ApT3HPJi9SgL/KkT2+U8hGQOkH8/am7ucQvO atdOY3fPcXq+q8ZHHJ4kiurHAaFZzDlj+kweZKajT4j0gNpZgrkKMce1Q6v94rIe rLeUqr0sCLgGQAw7hnrYFV+NDPpDgdYhnvIEEt83LrAs6i/DosrrCelo3Os4ovyE uqbpg7QJvANtPIbcd/UUw7mH2shObGda2emo+owRnjn/3PRBu3KNuvXx58kvDtDr PgpQctTNE3cF/Y8L3f97g1+w0bmHEUkFbofFQuuyk6fnryiS3yBGa6rQTjo8lXvt Bq2fpQD6gksix8MEAptINiayGeaeVmLNE8Elh3FBOP5f8f22iCZDuKZtpht+85dp MFGtVp0g8o2Z2SD50z4hu07wr3+b3KaQEO1ufgOoOGr2AV0Ra+kZcM5sElnxZWR0 cG2O9nB4vzS5IdnngA2z1aJegDG5Ct1b1coJ0GQtkjxkJBOd2/PZIGxS8mC3+KKg eG36iIntDuQ=phhS -----END PGP SIGNATURE----- -- RHSA-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.