RHSA-2022:1819: Moderate: go-toolset:rhel8 security and bug fix update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): golang: Command-line arguments may overwrite global data (CVE-2021-38297) golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196) (CVE-2021-39293) golang: debug/macho: invalid dynamic symbol table command can cause panic (CVE-2021-41771) golang: archive/zip: Reader.Open panics on empty string (CVE-2021-41772) golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString (CVE-2022-23772) golang: cmd/go: misinterpretation of branch names can lead to incorrect access control (CVE-2022-23773) golang: crypto/elliptic IsOnCurve returns true for invalid field elements (CVE-2022-23806) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1819?
The severity of RHSA-2022:1819 is classified as important.
How do I fix RHSA-2022:1819?
To fix RHSA-2022:1819, you need to update the affected packages to the recommended versions: 1.17.7-1.module+el8.6.0+14297+32a15e19 for go-toolset and golang, and 1.7.2-1.module+el8.6.0+12972+ebab5911 for delve.
What vulnerabilities are addressed in RHSA-2022:1819?
RHSA-2022:1819 addresses vulnerabilities including CVE-2021-38297 related to command-line arguments overwriting global data and a susceptibility in archive/zip for malformed archives.
Which packages are affected by RHSA-2022:1819?
The affected packages in RHSA-2022:1819 include golang, go-toolset, and delve.
Is there a CVE associated with RHSA-2022:1819?
Yes, RHSA-2022:1819 is associated with CVE-2021-38297, which concerns global data overwriting.