Several security issues were fixed in Go Networking.. ========================================================================== Ubuntu Security Notice USN-8089-1 March 12, 2026 golang-golang-x-net vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Go Networking. Software Description: - golang-golang-x-net: Supplementary Go networking libraries Details: Bahruz Jabiyev, Tommaso Innocenti, Anthony Gavazzi, Steven Sprecher, and Kaan Onarlioglu discovered that servers using Go Networking could hang during shutdown if preempted by a fatal error. An attacker could possibly use this to cause a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-27664) Arpad Ryszka and Jakob Ackermann discovered that a maliciously crafted stream could cause excessive CPU usage in Go Networking's HPACK decoder. An attacker could possibly use this to cause a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-41723) Mohammad Thoriq Aziz discovered that Go Networking did not properly sanitize some text nodes. An attacker could possibly use this to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-3978) Sean Ng discovered an error in Go Networking's HTML tag handling. An attacker could possibly use this to cause a denial of service. (CVE-2025-22872) Guido Vranken and Jakub Ciolek discovered that a maliciously crafted HTML document could exhaust system resources on servers using Go Networking. An attacker could possibly use this to cause a denial of service. (CVE-2025-47911) Guido Vranken discovered that a maliciously crafted HTML document could put servers using Go Networking into an infinite loop. An attacker could possibly use this to cause a denial of service. (CVE-2025-58190) Update instructions: The problem can be corrected by updating your system to thefollowing package versions: Ubuntu 24.04 LTS golang-golang-x-net-dev 1:0.21.0+dfsg-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS golang-golang-x-net-dev 1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8089-1 CVE-2022-27664, CVE-2022-41723, CVE-2023-3978, CVE-2025-22872, CVE-2025-47911, CVE-2025-58190 . Multiple security issues in Go Networking for Ubuntu affecting versions 22.04 LTS and 24.04 LTS, requiring urgent fixes.. Ubuntu 22.04 LTS, Go Networking, security updates, denial of service. . Severity: Important. LinuxSecurity.com Team
libpcap (Packet CAPture), a low-level network monitoring library, does not properly validate the PHB header length before allocating memory. This update added sanity checks for PHB header length. . Package : libpcap Version : 1.6.2-2+deb8u1 CVE ID : CVE-2019-15165 Debian Bug : 941697 libpcap (Packet CAPture), a low-level network monitoring library, does not properly validate the PHB header length before allocating memory. This update added sanity checks for PHB header length. For Debian 8 "Jessie", this problem has been fixed in version 1.6.2-2+deb8u1. We recommend that you upgrade your libpcap packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Follow these steps to upgrade libpcap on Debian 8 Jessie, addressing PHB header length validation vulnerabilities and improving memory safety. libpcap, network monitoring, security update, Debian Jessie, PHB header. . Severity: Critical. LinuxSecurity.com Team
lib: check for integer overflow in nlmsg_reserve() (rh#1440789, CVE-2017-0553). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-34f6e70fdd 2017-04-22 03:35:57.950856 --------------------------------------------------------------------------------Name : libnl3 Product : Fedora 25 Version : 3.2.29 Release : 3.fc25 URL : http://www.infradead.org/~tgr/libnl/ Summary : Convenience library for kernel netlink sockets Description : This package contains a convenience library to simplify using the Linux kernel's netlink sockets interface for network manipulation --------------------------------------------------------------------------------Update Information: lib: check for integer overflow in nlmsg_reserve() (rh#1440789, CVE-2017-0553) --------------------------------------------------------------------------------References: [ 1 ] Bug #1440789 - CVE-2017-0553 libnl3: libnl: Integer overflow in nlmsg_reserve() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1440789 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libnl3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
There is a bug in the part of libnids code responsible for TCP reassembly.The flaw probably allows remote code execution.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - --------------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200311-07 - - --------------------------------------------------------------------------- GLSA: 200311-07 package: net-libs/libnids summary: Libnids remote code execution severity: normal Gentoo bug: 32724 date: 2003-11-22 CVE: CAN-2003-0850 exploit: remote affected: =1.18 DESCRIPTION: There is a bug in the part of libnids code responsible for TCP reassembly. The flaw probably allows remote code execution. SOLUTION: It is recommended that all Gentoo Linux users who are running net-libs/libnids update their systems as follows: emerge sync emerge '> =net-libs/libnids-1.18' emerge clean - -- Andrea Barisani .*. Gentoo Linux Infrastructure Developer V ( ) GPG-Key 0xC9EE0905 ( ) 491D E9E0 3875 0EC9 10DD 150B CAA9 2C7D C9EE 0905 ^^_^^ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQE/wi78yqksfcnuCQURAmKjAJ0Y/K8Q8mbiwIvQCx44fgpNP0izoACfe4J0 q9x9uKfldu1ES92a1WP9Dyg=t5vz -----END PGP SIGNATURE----- . Important: Upgrade Gentoo's libnids to mitigate possible risks of remote code execution vulnerabilities.. libnids, Gentoo, remote code, execution risk. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.