RHSA-2023:1529MediumCVSS 7.5

Red Hat Security Advisory: Service Telemetry Framework 1.5 security update

Published
March 30, 2023
Last Modified
May 23, 2026

🔗 CVE IDs covered (15)

📋 Description

CVE-2022-1705 — golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-23772 — golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString CVE-2022-23773 — golang: cmd/go: misinterpretation of branch names can lead to incorrect access control CVE-2022-23806 — golang: crypto/elliptic: IsOnCurve returns true for invalid field elements CVE-2022-24675 — golang: encoding/pem: fix stack overflow in Decode CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-28327 — golang: crypto/elliptic: panic caused by oversized scalar CVE-2022-29526 — golang: syscall: faccessat checks wrong group CVE-2022-30629 — golang: crypto/tls: session tickets lack random ticket_age_add CVE-2022-30630 — golang: io/fs: stack exhaustion in Glob CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read CVE-2022-30632 — golang: path/filepath: stack exhaustion in Glob CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests

🔗 References (20)