RHBA-2023:6364MediumCVSS 7.5
Red Hat Bug Fix Advisory: golang and delve bug fix and enhancement update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-39318 — golang: html/template: improper handling of HTML-like comments within script contexts CVE-2023-39319 — golang: html/template: improper handling of special tags within script contexts CVE-2023-39321 — golang: crypto/tls: panic when processing post-handshake message on QUIC connections CVE-2023-39322 — golang: crypto/tls: lack of a limit on buffered post-handshake
🎯 Affected products22
- Red Hat Enterprise Linux AppStream (v. 9)
- delve-0:1.20.2-1.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- delve-0:1.20.2-1.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- delve-debuginfo-0:1.20.2-1.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- delve-debugsource-0:1.20.2-1.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.20.10-1.el9_3.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.20.10-1.el9_3.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.20.10-1.el9_3.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- go-toolset-0:1.20.10-1.el9_3.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.20.10-1.el9_3.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.20.10-1.el9_3.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.20.10-1.el9_3.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.20.10-1.el9_3.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-0:1.20.10-1.el9_3.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-bin-0:1.20.10-1.el9_3.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-bin-0:1.20.10-1.el9_3.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-bin-0:1.20.10-1.el9_3.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-bin-0:1.20.10-1.el9_3.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-docs-0:1.20.10-1.el9_3.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-misc-0:1.20.10-1.el9_3.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-src-0:1.20.10-1.el9_3.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- golang-tests-0:1.20.10-1.el9_3.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHBA-2023:6364
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.3_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2098211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2116995
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2117248
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167409
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186496
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2190184
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2230705
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhba-2023_6364.json