RHSA-2024:1462: Important: golang security update
Important: golang security update
Other sources
The golang packages provide the Go programming language compiler.Security Fix(es): golang: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3 - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3 - Upgrade
Upgrade
redhat/golang-docsto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3 - Upgrade
Upgrade
redhat/golang-miscto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3 - Upgrade
Upgrade
redhat/golang-srcto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3 - Upgrade
Upgrade
redhat/golang-teststo a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3.aa - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3.aa - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.20.12-2.el9_3.aa - Compensating control
Make sure all previously released errata relevant to your system have been applied before updating the golang packages.
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1462?
The severity of RHSA-2024:1462 is classified as important.
How do I fix RHSA-2024:1462?
To resolve RHSA-2024:1462, update the golang packages to version 1.20.12-2.el9_3.
What vulnerabilities are addressed in RHSA-2024:1462?
RHSA-2024:1462 addresses memory leaks in code encrypting and decrypting RSA payloads as detailed in CVE-2024-1394.
What packages are affected by RHSA-2024:1462?
RHSA-2024:1462 affects several golang packages including golang, golang-bin, go-toolset, and others.
Who is impacted by RHSA-2024:1462?
Users of Red Hat's golang packages on RHEL platforms, especially those utilizing affected versions, are impacted by RHSA-2024:1462.