First published: Tue May 10 2022(Updated: )
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. <br>Security Fix(es):<br><li> golang: Command-line arguments may overwrite global data (CVE-2021-38297)</li> <li> golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196) (CVE-2021-39293)</li> <li> golang: debug/macho: invalid dynamic symbol table command can cause panic (CVE-2021-41771)</li> <li> golang: archive/zip: Reader.Open panics on empty string (CVE-2021-41772)</li> <li> golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString (CVE-2022-23772)</li> <li> golang: cmd/go: misinterpretation of branch names can lead to incorrect access control (CVE-2022-23773)</li> <li> golang: crypto/elliptic IsOnCurve returns true for invalid field elements (CVE-2022-23806)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/delve | <1.7.2-1.module+el8.6.0+12972+ebab5911 | 1.7.2-1.module+el8.6.0+12972+ebab5911 |
redhat/go-toolset | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/delve | <1.7.2-1.module+el8.6.0+12972+ebab5911 | 1.7.2-1.module+el8.6.0+12972+ebab5911 |
redhat/delve-debuginfo | <1.7.2-1.module+el8.6.0+12972+ebab5911 | 1.7.2-1.module+el8.6.0+12972+ebab5911 |
redhat/delve-debugsource | <1.7.2-1.module+el8.6.0+12972+ebab5911 | 1.7.2-1.module+el8.6.0+12972+ebab5911 |
redhat/go-toolset | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang-bin | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang-docs | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang-misc | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang-race | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang-src | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang-tests | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang-bin | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/go-toolset | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/golang-bin | <1.17.7-1.module+el8.6.0+14297+32a15e19 | 1.17.7-1.module+el8.6.0+14297+32a15e19 |
redhat/go-toolset | <1.17.7-1.module+el8.6.0+14297+32a15e19.aa | 1.17.7-1.module+el8.6.0+14297+32a15e19.aa |
redhat/golang | <1.17.7-1.module+el8.6.0+14297+32a15e19.aa | 1.17.7-1.module+el8.6.0+14297+32a15e19.aa |
redhat/golang-bin | <1.17.7-1.module+el8.6.0+14297+32a15e19.aa | 1.17.7-1.module+el8.6.0+14297+32a15e19.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.