RHSA-2021:3585: Moderate: go-toolset:rhel8 security update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet (CVE-2021-29923) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/delveto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.4.0+8864+58b0fcdb - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-docsto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-miscto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-srcto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-teststo a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/delve-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.4.0+8864+58b0fcdb - Upgrade
Upgrade
redhat/delve-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.4.0+8864+58b0fcdb - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473.aa - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473.aa - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473.aa - Upgrade
Upgrade
golangto a version that resolves this vulnerability.Patch go-toolset:rhel8 security update
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3585?
The vulnerability is classified as moderate severity.
How do I fix RHSA-2021:3585?
You can fix RHSA-2021:3585 by updating to the recommended package versions, such as golang 1.15.14-2.module+el8.4.0+12542+e3fec473.
What does the vulnerability in RHSA-2021:3585 affect?
RHSA-2021:3585 affects the Go Toolset and associated packages due to incorrect parsing of IP address octets.
What specific CVE is associated with RHSA-2021:3585?
RHSA-2021:3585 is associated with CVE-2021-29923.
Which packages need to be updated for RHSA-2021:3585?
Packages that need updates include golang, go-toolset, and delve, among others.