RHSA-2023:0446: Moderate: go-toolset:rhel8 security and bug fix update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879) golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880) golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Internal linking fails on ppc64le (BZ#2144545) crypto testcases fail on golang on s390x [rhel-8] (BZ#2149313)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/delveto a version that resolves this vulnerability.Fixed in 1.8.3-1.module+el8.7.0+15126+0e0a42d9 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17845+708ebe87 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675 - Upgrade
Upgrade
redhat/golang-docsto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675 - Upgrade
Upgrade
redhat/golang-miscto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675 - Upgrade
Upgrade
redhat/golang-srcto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675 - Upgrade
Upgrade
redhat/golang-teststo a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675 - Upgrade
Upgrade
redhat/delve-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-1.module+el8.7.0+15126+0e0a42d9 - Upgrade
Upgrade
redhat/delve-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.3-1.module+el8.7.0+15126+0e0a42d9 - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675 - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17845+708ebe87.aa - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675.aa - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.18.9-1.module+el8.7.0+17640+84246675.aa - Upgrade
Upgrade
go-toolset:rhel8to a version that resolves this vulnerability.Patch CVE-2022-2879 - Upgrade
Upgrade
go-toolset:rhel8to a version that resolves this vulnerability.Patch CVE-2022-2880 - Upgrade
Upgrade
go-toolset:rhel8to a version that resolves this vulnerability.Patch CVE-2022-41715 - Upgrade
Upgrade
go-toolset:rhel8to a version that resolves this vulnerability.Patch BZ#2149313 - Upgrade
Upgrade
go-toolset:rhel8to a version that resolves this vulnerability.Patch BZ#2144545
Event History
Frequently Asked Questions
What are the security vulnerabilities associated with RHSA-2023:0446?
The vulnerabilities include unbounded memory consumption in the 'archive/tar' package and issues in 'net/http/httputil: ReverseProxy'.
How do I fix RHSA-2023:0446?
To fix RHSA-2023:0446, update the affected packages to the specified remedied versions.
What is the impact of the vulnerability identified in RHSA-2023:0446?
The vulnerability could lead to excessive memory consumption, potentially causing denial of service.
Which packages are affected by RHSA-2023:0446?
Affected packages include delve, go-toolset, golang, golang-docs, golang-misc, and others.
Is there a recommended version to upgrade to for fixing RHSA-2023:0446?
Yes, upgrade to the specified versions such as delve 1.8.3 and golang 1.18.9.