[openSUSE-SU-2021:2392-1] Security update for go1.16

Severity Important
Affected Packages 10
CVEs 1

Security update for go1.16

This update for go1.16 fixes the following issues:

go1.16.6 (released 2021-07-12, bsc#1182345) includes a security fix to the
crypto/tls package, as well as bug fixes to the compiler, and the
net and net/http packages.

Security issue fixed:

CVE-2021-34558: Fixed crypto/tls: clients can panic when provided a certificate of the wrong type for the negotiated parameters (bsc#1188229)

go1.16 release:

  • bsc#1188229 go#47143 CVE-2021-34558
  • go#47145 security: fix CVE-2021-34558
  • go#46999 net: LookupMX behaviour broken
  • go#46981 net: TestCVE202133195 fails if /etc/resolv.conf specifies ndots larger than 3
  • go#46769 syscall: TestGroupCleanupUserNamespace test failure on Fedora
  • go#46657 runtime: deeply nested struct initialized with non-zero values
  • go#44984 net/http: server not setting Content-Length in certain cases
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/go1.16?arch=x86_64&distro=opensuse-leap-15.3 opensuse go1.16 < 1.16.6-1.20.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/go1.16?arch=s390x&distro=opensuse-leap-15.3 opensuse go1.16 < 1.16.6-1.20.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/opensuse/go1.16?arch=ppc64le&distro=opensuse-leap-15.3 opensuse go1.16 < 1.16.6-1.20.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/opensuse/go1.16?arch=aarch64&distro=opensuse-leap-15.3 opensuse go1.16 < 1.16.6-1.20.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/opensuse/go1.16-race?arch=x86_64&distro=opensuse-leap-15.3 opensuse go1.16-race < 1.16.6-1.20.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/go1.16-race?arch=aarch64&distro=opensuse-leap-15.3 opensuse go1.16-race < 1.16.6-1.20.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/opensuse/go1.16-doc?arch=x86_64&distro=opensuse-leap-15.3 opensuse go1.16-doc < 1.16.6-1.20.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/go1.16-doc?arch=s390x&distro=opensuse-leap-15.3 opensuse go1.16-doc < 1.16.6-1.20.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/opensuse/go1.16-doc?arch=ppc64le&distro=opensuse-leap-15.3 opensuse go1.16-doc < 1.16.6-1.20.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/opensuse/go1.16-doc?arch=aarch64&distro=opensuse-leap-15.3 opensuse go1.16-doc < 1.16.6-1.20.1 opensuse-leap-15.3 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date