[SUSE-SU-2023:0869-1] Security update for go1.18
Severity
Important
Affected Packages
20
CVEs
3
Security update for go1.18
This update for go1.18 fixes the following issues:
- CVE-2022-41723: Fixed a quadratic complexity in HPACK decoding in net/http (bsc#1208270).
- CVE-2022-41724: Fixed a denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208271).
- CVE-2022-41725: Fixed a panic with large handshake records in crypto/tls (bsc#1208272).
The following non-security bug was fixed:
- Fixed PTF ref:_00D1igLOd._5005qM0AP4:ref SG#65262 (bsc#1208491).
- ID
- SUSE-SU-2023:0869-1
- Severity
- important
- URL
- https://www.suse.com/support/update/announcement/2023/suse-su-20230869-1/
- Published
-
2023-03-22T08:43:41
(18 months ago) - Modified
-
2023-03-22T08:43:41
(18 months ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALAS-2023-1731
- ALAS-2023-1825
- ALAS-2023-1848
- ALAS-2023-1849
- ALAS-2023-1866
- ALAS-2023-1881
- ALAS2-2023-2015
- ALAS2-2023-2143
- ALAS2-2023-2163
- ALAS2-2023-2192
- ALAS2-2023-2193
- ALAS2-2023-2194
- ALAS2-2023-2238
- ALAS2-2023-2303
- ALPINE:CVE-2022-41723
- ALPINE:CVE-2022-41724
- ALPINE:CVE-2022-41725
- ALSA-2023:3083
- ALSA-2023:6346
- ALSA-2023:6363
- ALSA-2023:6380
- ALSA-2023:6402
- ALSA-2023:6473
- ALSA-2023:6474
- ALSA-2023:6938
- ALSA-2023:6939
- ELSA-2023-3083
- ELSA-2023-6363
- ELSA-2023-6380
- ELSA-2023-6402
- ELSA-2023-6473
- ELSA-2023-6474
- ELSA-2023-6938
- ELSA-2023-6939
- FEDORA-2023-28c182b657
- FEDORA-2023-327346caa5
- FEDORA-2023-3737bc1c0a
- FEDORA-2023-8c02aee138
- FEDORA-2023-a5a5542890
- FEDORA-2023-abb47e24d8
- FEDORA-2023-ca444fdecf
- FEDORA-2023-cb20f08a4e
- FEDORA-2023-ccaf5538dd
- FEDORA-2023-e359fd31d2
- FREEBSD:3D73E384-AD1F-11ED-983C-83FE35862E3A
- GLSA-202311-09
- GO-2023-1569
- GO-2023-1570
- GO-2023-1571
- MS:CVE-2022-41723
- RHBA-2023:2181
- RHSA-2023:3083
- RHSA-2023:6346
- RHSA-2023:6363
- RHSA-2023:6380
- RHSA-2023:6402
- RHSA-2023:6473
- RHSA-2023:6474
- RHSA-2023:6938
- RHSA-2023:6939
- RHSA-2023:7058
- SUSE-SU-2023:0733-1
- SUSE-SU-2023:0735-1
- SUSE-SU-2023:0811-1
- SUSE-SU-2023:0812-1
- SUSE-SU-2023:0821-1
- SUSE-SU-2023:0871-1
- SUSE-SU-2023:2312-1
- SUSE-SU-2023:2598-1
- SUSE-SU-2023:3867-1
- SUSE-SU-2023:3868-1
- SUSE-SU-2023:3875-1
- SUSE-SU-2023:4124-1
- SUSE-SU-2024:0191-1
- SUSE-SU-2024:0196-1
- SUSE-SU-2024:3288-1
- USN-6140-1
Source | # ID | Name | URL |
---|---|---|---|
Suse | SUSE ratings | https://www.suse.com/support/security/rating/ | |
Suse | URL of this CSAF notice | https://ftp.suse.com/pub/projects/security/csaf/suse-su-2023_0869-1.json | |
Suse | URL for SUSE-SU-2023:0869-1 | https://www.suse.com/support/update/announcement/2023/suse-su-20230869-1/ | |
Suse | E-Mail link for SUSE-SU-2023:0869-1 | https://lists.suse.com/pipermail/sle-security-updates/2023-March/014132.html | |
Bugzilla | SUSE Bug 1208270 | https://bugzilla.suse.com/1208270 | |
Bugzilla | SUSE Bug 1208271 | https://bugzilla.suse.com/1208271 | |
Bugzilla | SUSE Bug 1208272 | https://bugzilla.suse.com/1208272 | |
Bugzilla | SUSE Bug 1208491 | https://bugzilla.suse.com/1208491 | |
CVE | SUSE CVE CVE-2022-41723 page | https://www.suse.com/security/cve/CVE-2022-41723/ | |
CVE | SUSE CVE CVE-2022-41724 page | https://www.suse.com/security/cve/CVE-2022-41724/ | |
CVE | SUSE CVE CVE-2022-41725 page | https://www.suse.com/security/cve/CVE-2022-41725/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/suse/go1.18?arch=x86_64&distro=sles-15&sp=3 | suse | go1.18 | < 1.18.10-150000.1.46.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/go1.18?arch=x86_64&distro=opensuse-leap-15.4 | suse | go1.18 | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/go1.18?arch=s390x&distro=sles-15&sp=3 | suse | go1.18 | < 1.18.10-150000.1.46.1 | sles-15 | s390x | |
Affected | pkg:rpm/suse/go1.18?arch=s390x&distro=opensuse-leap-15.4 | suse | go1.18 | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/go1.18?arch=ppc64le&distro=sles-15&sp=3 | suse | go1.18 | < 1.18.10-150000.1.46.1 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/go1.18?arch=ppc64le&distro=opensuse-leap-15.4 | suse | go1.18 | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/go1.18?arch=aarch64&distro=sles-15&sp=3 | suse | go1.18 | < 1.18.10-150000.1.46.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/go1.18?arch=aarch64&distro=opensuse-leap-15.4 | suse | go1.18 | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | aarch64 | |
Affected | pkg:rpm/suse/go1.18-race?arch=x86_64&distro=sles-15&sp=3 | suse | go1.18-race | < 1.18.10-150000.1.46.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/go1.18-race?arch=x86_64&distro=opensuse-leap-15.4 | suse | go1.18-race | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/go1.18-race?arch=aarch64&distro=sles-15&sp=3 | suse | go1.18-race | < 1.18.10-150000.1.46.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/go1.18-race?arch=aarch64&distro=opensuse-leap-15.4 | suse | go1.18-race | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | aarch64 | |
Affected | pkg:rpm/suse/go1.18-doc?arch=x86_64&distro=sles-15&sp=3 | suse | go1.18-doc | < 1.18.10-150000.1.46.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/go1.18-doc?arch=x86_64&distro=opensuse-leap-15.4 | suse | go1.18-doc | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/go1.18-doc?arch=s390x&distro=sles-15&sp=3 | suse | go1.18-doc | < 1.18.10-150000.1.46.1 | sles-15 | s390x | |
Affected | pkg:rpm/suse/go1.18-doc?arch=s390x&distro=opensuse-leap-15.4 | suse | go1.18-doc | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/go1.18-doc?arch=ppc64le&distro=sles-15&sp=3 | suse | go1.18-doc | < 1.18.10-150000.1.46.1 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/go1.18-doc?arch=ppc64le&distro=opensuse-leap-15.4 | suse | go1.18-doc | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/go1.18-doc?arch=aarch64&distro=sles-15&sp=3 | suse | go1.18-doc | < 1.18.10-150000.1.46.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/go1.18-doc?arch=aarch64&distro=opensuse-leap-15.4 | suse | go1.18-doc | < 1.18.10-150000.1.46.1 | opensuse-leap-15.4 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |