RHBA-2023:2181MediumCVSS 7.5
Red Hat Bug Fix Advisory: delve, golang, and go-toolset bug fix and enhancement update
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2022-41724 — golang: crypto/tls: large handshake records may cause panics CVE-2022-41725 — golang: net/http, mime/multipart: denial of service from excessive resource consumption
🎯 Affected products24
- Red Hat Enterprise Linux AppStream (v. 9)
- delve-0:1.9.1-1.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- delve-0:1.9.1-1.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- delve-debuginfo-0:1.9.1-1.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- delve-debugsource-0:1.9.1-1.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.19.6-2.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.19.6-2.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.19.6-2.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.19.6-2.el9_2.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.19.6-2.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.19.6-2.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.19.6-2.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.19.6-2.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.19.6-2.el9_2.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.19.6-2.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-bin-0:1.19.6-2.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-bin-0:1.19.6-2.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-bin-0:1.19.6-2.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-bin-0:1.19.6-2.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-docs-0:1.19.6-2.el9_2.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-misc-0:1.19.6-2.el9_2.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-race-0:1.19.6-2.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-src-0:1.19.6-2.el9_2.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-tests-0:1.19.6-2.el9_2.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHBA-2023:2181
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966992
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133019
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2137763
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2138231
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2157587
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhba-2023_2181.json