First published: Tue Sep 10 2019(Updated: )
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.<br>Security Fix(es):<br><li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Failure trying to conntect to image registry using TLS when buildah is compiled with FIPS mode (BZ#1743169)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/go-toolset | <1.11.13-1.module+el8.0.1+4087+d8180914 | 1.11.13-1.module+el8.0.1+4087+d8180914 |
redhat/golang | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/golang-docs | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/golang-misc | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/golang-src | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/golang-tests | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/go-toolset | <1.11.13-1.module+el8.0.1+4087+d8180914 | 1.11.13-1.module+el8.0.1+4087+d8180914 |
redhat/golang | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/golang-bin | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/golang-race | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/golang-bin | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/go-toolset | <1.11.13-1.module+el8.0.1+4087+d8180914 | 1.11.13-1.module+el8.0.1+4087+d8180914 |
redhat/golang | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/golang-bin | <1.11.13-2.module+el8.0.1+4087+d8180914 | 1.11.13-2.module+el8.0.1+4087+d8180914 |
redhat/go-toolset | <1.11.13-1.module+el8.0.1+4087+d8180914.aa | 1.11.13-1.module+el8.0.1+4087+d8180914.aa |
redhat/golang | <1.11.13-2.module+el8.0.1+4087+d8180914.aa | 1.11.13-2.module+el8.0.1+4087+d8180914.aa |
redhat/golang-bin | <1.11.13-2.module+el8.0.1+4087+d8180914.aa | 1.11.13-2.module+el8.0.1+4087+d8180914.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2019:2726 is critical due to the potential for unbounded memory growth in HTTP/2 implementations.
To fix RHSA-2019:2726, update the affected packages to the versions specified in the advisory, such as go-toolset-1.11.13-1.module+el8.0.1+4087+d8180914 or golang-1.11.13-2.module+el8.0.1+4087+d8180914.
RHSA-2019:2726 affects packages including go-toolset, golang, golang-docs, and several others related to the Go programming language.
RHSA-2019:2726 addresses vulnerabilities including CVE-2019-9512 which allows for flooding using PING and HEADERS frames in HTTP/2.
There are no specific workarounds listed for RHSA-2019:2726; applying the recommended updates is the best mitigation.