RHSA-2023:3083MediumCVSS 7.5

Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update

Published
May 16, 2023
Last Modified
September 19, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2022-41724 — golang: crypto/tls: large handshake records may cause panics CVE-2022-41725 — golang: net/http, mime/multipart: denial of service from excessive resource consumption

🎯 Affected products24

  • Red Hat Enterprise Linux AppStream (v. 8)
  • delve-0:1.9.1-1.module+el8.8.0+16778+5fbb74f5.src (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • delve-0:1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • delve-debuginfo-0:1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • delve-debugsource-0:1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • go-toolset-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.aarch64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • go-toolset-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.ppc64le (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • go-toolset-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.s390x (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • go-toolset-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.src (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • go-toolset-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.x86_64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.aarch64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.ppc64le (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.s390x (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.src (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.x86_64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-bin-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.aarch64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-bin-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.ppc64le (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-bin-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.s390x (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-bin-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.x86_64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-docs-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.noarch (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-misc-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.noarch (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-race-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.x86_64 (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-src-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.noarch (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • golang-tests-0:1.19.6-1.module+el8.8.0+18289+edd6c8b6.noarch (go-toolset:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (6)