[GLSA-202209-26] Go: Multiple Vulnerabilities

Severity Low
Affected Packages 1
Unaffected Packages 1
CVEs 2

Multiple vulnerabilities have been discovered in Go, the worst of which could result in denial of service.

Background
Go is an open source programming language that makes it easy to build simple, reliable, and efficient software.

Description
Multiple vulnerabilities have been discovered in Go. Please review the CVE identifiers referenced below for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All Go users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/go-1.18.6"

In addition, users using Portage 3.0.9 or later should ensure that packages with Go binaries have no vulnerable code statically linked into their binaries by rebuilding the @golang-rebuild set:

# emerge --ask --oneshot --verbose @golang-rebuild

Package Affected Version
pkg:ebuild/dev-lang/go?distro=gentoo < 1.18.6
Package Unaffected Version
pkg:ebuild/dev-lang/go?distro=gentoo >= 1.18.6
Source # ID Name URL
CVE CVE-2022-27664 CVE-2022-27664 https://nvd.nist.gov/vuln/detail/CVE-2022-27664
CVE CVE-2022-32190 CVE-2022-32190 https://nvd.nist.gov/vuln/detail/CVE-2022-32190
Bugzilla 869002 Bugzilla #869002 https://bugs.gentoo.org/show_bug.cgi?id=869002
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/dev-lang/go?distro=gentoo dev-lang go < 1.18.6 gentoo
Unaffected pkg:ebuild/dev-lang/go?distro=gentoo dev-lang go >= 1.18.6 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...