RHSA-2024:1041: Moderate: go-toolset-1.19-golang security update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.<br>Security Fix(es):<br><li> golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)</li> <li> golang: cmd/go: Protocol Fallback when fetching modules (CVE-2023-45285)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: go-toolset-1.19-golang security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1041?
The severity of RHSA-2024:1041 is categorized as a Denial of Service (DoS) vulnerability.
How do I fix RHSA-2024:1041?
To fix RHSA-2024:1041, update to the fixed versions of the packages as specified, such as 1.19-golang-1.19.13-5.el7_9.
Which packages are affected by RHSA-2024:1041?
The affected packages include go-toolset versions prior to 1.19-golang-1.19.13-5.el7_9.
What specific vulnerability does RHSA-2024:1041 address?
RHSA-2024:1041 addresses a Denial of Service vulnerability via Resource Consumption through HTTP requests, identified as CVE-2023-39326.
Is RHSA-2024:1041 applicable to all Red Hat systems?
RHSA-2024:1041 specifically applies to certain systems using the Red Hat Developer Tools for RHEL Server for System Z.