RHSA-2023:0445: Moderate: go-toolset-1.18 security update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.<br>Security Fix(es):<br><li> golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879)</li> <li> golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)</li> <li> golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> crypto testcases fail on golang on s390x [devtools-2022.4] (BZ#2149315)</li> <li> Internal linking fails on ppc64le [devtools-2022.4] (BZ#2161298)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0445?
The severity of RHSA-2023:0445 is classified as critical due to vulnerabilities that can lead to unbounded memory consumption.
How do I fix RHSA-2023:0445?
To fix RHSA-2023:0445, upgrade to the latest versions of the Go Toolset provided by Red Hat.
What vulnerabilities are addressed in RHSA-2023:0445?
RHSA-2023:0445 addresses vulnerabilities including unbounded memory consumption in archive/tar and improper handling in net/http/httputil.
Which packages are affected by RHSA-2023:0445?
The affected packages include various versions of the Go Toolset, such as golang and related build tools.
When was RHSA-2023:0445 released?
RHSA-2023:0445 was released to address critical vulnerabilities in the Go Toolset.