First published: Thu May 16 2024(Updated: )
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. <br>Security Fix(es):<br><li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/go-toolset | <1.19-golang-1.19.13-7.el7_9 | 1.19-golang-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-1.19.13-7.el7_9 | 1.19-golang-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-bin-1.19.13-7.el7_9 | 1.19-golang-bin-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-docs-1.19.13-7.el7_9 | 1.19-golang-docs-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-misc-1.19.13-7.el7_9 | 1.19-golang-misc-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-race-1.19.13-7.el7_9 | 1.19-golang-race-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-src-1.19.13-7.el7_9 | 1.19-golang-src-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-tests-1.19.13-7.el7_9 | 1.19-golang-tests-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-bin-1.19.13-7.el7_9 | 1.19-golang-bin-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-misc-1.19.13-7.el7_9 | 1.19-golang-misc-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-src-1.19.13-7.el7_9 | 1.19-golang-src-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-tests-1.19.13-7.el7_9 | 1.19-golang-tests-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-1.19.13-7.el7_9 | 1.19-golang-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-bin-1.19.13-7.el7_9 | 1.19-golang-bin-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-misc-1.19.13-7.el7_9 | 1.19-golang-misc-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-src-1.19.13-7.el7_9 | 1.19-golang-src-1.19.13-7.el7_9 |
redhat/go-toolset | <1.19-golang-tests-1.19.13-7.el7_9 | 1.19-golang-tests-1.19.13-7.el7_9 |
Red Hat Developer Tools | ||
Red Hat Developer Tools | ||
Red Hat Developer Tools | ||
Red Hat Developer Tools |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2024:2892 is classified as important due to a denial of service vulnerability in the Go programming language.
To fix RHSA-2024:2892, update to the specified package version 1.19-golang-1.19.13-7.el7_9 or higher.
RHSA-2024:2892 affects multiple Red Hat Developer Tools packages across various RHEL environments.
There are no known workarounds for RHSA-2024:2892; applying the security update is the recommended action.
CVE-2023-45288 describes a vulnerability in the Go language's net/http and x/net/http2 packages that allows for a denial of service attack.