[ALSA-2021:3076] go-toolset:rhel8 security, bug fix, and enhancement update

Severity Moderate
Affected Packages 8
CVEs 4

An update for the go-toolset:rhel8 module is now available for AlmaLinux AlmaLinux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

The following packages have been upgraded to a later upstream version: golang (1.15.14). (BZ#1982287)

Security Fix(es):

  • golang: encoding/xml: infinite loop when using xml.NewTokenDecoder with a custom TokenReader (CVE-2021-27918)

  • golang: net/http: panic in ReadRequest and ReadResponse when reading a very large header (CVE-2021-31525)

  • golang: archive/zip: malformed archive may cause panic or memory exhaustion (CVE-2021-33196)

  • golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • FIPS mode AES CBC CryptBlocks incorrectly re-initializes IV in file crypto/internal/boring/aes.go (BZ#1978567)

  • FIPS mode AES CBC Decrypter produces incorrect result (BZ#1983976)

Package Affected Version
pkg:rpm/almalinux/golang?arch=x86_64&distro=almalinux-8.4 < 1.15.14-1.module_el8.4.0+2519+614b07b8
pkg:rpm/almalinux/golang-tests?arch=noarch&distro=almalinux-8.4 < 1.15.14-1.module_el8.4.0+2519+614b07b8
pkg:rpm/almalinux/golang-src?arch=noarch&distro=almalinux-8.4 < 1.15.14-1.module_el8.4.0+2519+614b07b8
pkg:rpm/almalinux/golang-race?arch=x86_64&distro=almalinux-8.4 < 1.15.14-1.module_el8.4.0+2519+614b07b8
pkg:rpm/almalinux/golang-misc?arch=noarch&distro=almalinux-8.4 < 1.15.14-1.module_el8.4.0+2519+614b07b8
pkg:rpm/almalinux/golang-docs?arch=noarch&distro=almalinux-8.4 < 1.15.14-1.module_el8.4.0+2519+614b07b8
pkg:rpm/almalinux/golang-bin?arch=x86_64&distro=almalinux-8.4 < 1.15.14-1.module_el8.4.0+2519+614b07b8
pkg:rpm/almalinux/go-toolset?arch=x86_64&distro=almalinux-8.4 < 1.15.14-1.module_el8.4.0+2519+614b07b8
ID
ALSA-2021:3076
Severity
moderate
URL
https://errata.almalinux.org/ALSA-2021:3076.html
Published
2021-08-10T12:00:58
(3 years ago)
Modified
2021-08-11T13:42:14
(3 years ago)
Rights
Copyright 2021 AlmaLinux OS
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/almalinux/golang?arch=x86_64&distro=almalinux-8.4 almalinux golang < 1.15.14-1.module_el8.4.0+2519+614b07b8 almalinux-8.4 x86_64
Affected pkg:rpm/almalinux/golang-tests?arch=noarch&distro=almalinux-8.4 almalinux golang-tests < 1.15.14-1.module_el8.4.0+2519+614b07b8 almalinux-8.4 noarch
Affected pkg:rpm/almalinux/golang-src?arch=noarch&distro=almalinux-8.4 almalinux golang-src < 1.15.14-1.module_el8.4.0+2519+614b07b8 almalinux-8.4 noarch
Affected pkg:rpm/almalinux/golang-race?arch=x86_64&distro=almalinux-8.4 almalinux golang-race < 1.15.14-1.module_el8.4.0+2519+614b07b8 almalinux-8.4 x86_64
Affected pkg:rpm/almalinux/golang-misc?arch=noarch&distro=almalinux-8.4 almalinux golang-misc < 1.15.14-1.module_el8.4.0+2519+614b07b8 almalinux-8.4 noarch
Affected pkg:rpm/almalinux/golang-docs?arch=noarch&distro=almalinux-8.4 almalinux golang-docs < 1.15.14-1.module_el8.4.0+2519+614b07b8 almalinux-8.4 noarch
Affected pkg:rpm/almalinux/golang-bin?arch=x86_64&distro=almalinux-8.4 almalinux golang-bin < 1.15.14-1.module_el8.4.0+2519+614b07b8 almalinux-8.4 x86_64
Affected pkg:rpm/almalinux/go-toolset?arch=x86_64&distro=almalinux-8.4 almalinux go-toolset < 1.15.14-1.module_el8.4.0+2519+614b07b8 almalinux-8.4 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...