RHSA-2019:2726: Important: go-toolset:rhel8 security and bug fix update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.Security Fix(es): HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512) HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Failure trying to conntect to image registry using TLS when buildah is compiled with FIPS mode (BZ#1743169)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2726?
The severity of RHSA-2019:2726 is critical due to the potential for unbounded memory growth in HTTP/2 implementations.
How do I fix RHSA-2019:2726?
To fix RHSA-2019:2726, update the affected packages to the versions specified in the advisory, such as go-toolset-1.11.13-1.module+el8.0.1+4087+d8180914 or golang-1.11.13-2.module+el8.0.1+4087+d8180914.
Which packages are affected by RHSA-2019:2726?
RHSA-2019:2726 affects packages including go-toolset, golang, golang-docs, and several others related to the Go programming language.
What are the vulnerabilities addressed in RHSA-2019:2726?
RHSA-2019:2726 addresses vulnerabilities including CVE-2019-9512 which allows for flooding using PING and HEADERS frames in HTTP/2.
Is there a workaround for RHSA-2019:2726?
There are no specific workarounds listed for RHSA-2019:2726; applying the recommended updates is the best mitigation.