RHSA-2022:6113: Important: Red Hat Application Interconnect 1.0 Release (rpms)
This release addresses several security issues in the underlying golang compiler by moving to golang version 1.17.12.Security Fixes:Important: golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631) Moderate: golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705) golang: go/parser: stack exhaustion in all Parse functions (CVE-2022-1962) golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131) golang: io/fs: stack exhaustion in Glob (CVE-2022-30630) golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632) golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633) golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)For more details about the security issue(s), including the impact; a CVSSscore; acknowledgments; and other related information refer to the CVE page(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6113?
The severity of RHSA-2022:6113 is categorized as Important due to issues like stack exhaustion in the golang compress/gzip package.
How do I fix RHSA-2022:6113?
To fix RHSA-2022:6113, update to the golang version included in the release, particularly version 1.17.12.
What vulnerabilities are addressed in RHSA-2022:6113?
RHSA-2022:6113 addresses CVE-2022-30631 and other security issues related to the golang compiler.
Which software is affected by RHSA-2022:6113?
RHSA-2022:6113 affects the skupper-cli package on Red Hat Enterprise Linux 8.
When was RHSA-2022:6113 released?
RHSA-2022:6113 was released to address security vulnerabilities discovered in the golang compiler components.