[ALAS2-2023-1926] Amazon Linux 2 2017.12 - ALAS2-2023-1926: medium priority package update for golang

Severity Medium
Affected Packages 11
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2022-41717:
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

ID
ALAS2-2023-1926
Severity
medium
URL
https://alas.aws.amazon.com/AL2/ALAS-2023-1926.html
Published
2023-01-30T16:02:00
(19 months ago)
Modified
2023-02-04T18:28:00
(19 months ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/golang?arch=x86_64&distro=amazonlinux-2 amazonlinux golang < 1.18.9-1.amzn2.0.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/golang?arch=aarch64&distro=amazonlinux-2 amazonlinux golang < 1.18.9-1.amzn2.0.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/golang-tests?arch=noarch&distro=amazonlinux-2 amazonlinux golang-tests < 1.18.9-1.amzn2.0.1 amazonlinux-2 noarch
Affected pkg:rpm/amazonlinux/golang-src?arch=noarch&distro=amazonlinux-2 amazonlinux golang-src < 1.18.9-1.amzn2.0.1 amazonlinux-2 noarch
Affected pkg:rpm/amazonlinux/golang-shared?arch=x86_64&distro=amazonlinux-2 amazonlinux golang-shared < 1.18.9-1.amzn2.0.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/golang-shared?arch=aarch64&distro=amazonlinux-2 amazonlinux golang-shared < 1.18.9-1.amzn2.0.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/golang-race?arch=x86_64&distro=amazonlinux-2 amazonlinux golang-race < 1.18.9-1.amzn2.0.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/golang-misc?arch=noarch&distro=amazonlinux-2 amazonlinux golang-misc < 1.18.9-1.amzn2.0.1 amazonlinux-2 noarch
Affected pkg:rpm/amazonlinux/golang-docs?arch=noarch&distro=amazonlinux-2 amazonlinux golang-docs < 1.18.9-1.amzn2.0.1 amazonlinux-2 noarch
Affected pkg:rpm/amazonlinux/golang-bin?arch=x86_64&distro=amazonlinux-2 amazonlinux golang-bin < 1.18.9-1.amzn2.0.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/golang-bin?arch=aarch64&distro=amazonlinux-2 amazonlinux golang-bin < 1.18.9-1.amzn2.0.1 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...