RHSA-2021:3585: Moderate: go-toolset:rhel8 security update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet (CVE-2021-29923) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/delveto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.4.0+8864+58b0fcdb - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-docsto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-miscto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-srcto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-teststo a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/delve-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.4.0+8864+58b0fcdb - Upgrade
Upgrade
redhat/delve-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.4.0+8864+58b0fcdb - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473.aa - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473.aa - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.15.14-2.module+el8.4.0+12542+e3fec473.aa - Upgrade
Upgrade
go-toolset module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in go-toolset-1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
delve module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in delve-1.5.0-2.module+el8.4.0+8864+58b0fcdb - Upgrade
Upgrade
golang module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in golang-1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
golang-bin module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in golang-bin-1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
golang-docs module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in golang-docs-1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
golang-misc module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in golang-misc-1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
golang-race module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in golang-race-1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
golang-src module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in golang-src-1.15.14-2.module+el8.4.0+12542+e3fec473 - Upgrade
Upgrade
golang-tests module on RHEL 8 (el8.4.0)to a version that resolves this vulnerability.Fixed in golang-tests-1.15.14-2.module+el8.4.0+12542+e3fec473
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3585?
The vulnerability is classified as moderate severity.
How do I fix RHSA-2021:3585?
You can fix RHSA-2021:3585 by updating to the recommended package versions, such as golang 1.15.14-2.module+el8.4.0+12542+e3fec473.
What does the vulnerability in RHSA-2021:3585 affect?
RHSA-2021:3585 affects the Go Toolset and associated packages due to incorrect parsing of IP address octets.
What specific CVE is associated with RHSA-2021:3585?
RHSA-2021:3585 is associated with CVE-2021-29923.
Which packages need to be updated for RHSA-2021:3585?
Packages that need updates include golang, go-toolset, and delve, among others.