RHSA-2024:2892: Important: go-toolset-1.19-golang security update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)
Other sources
Important: go-toolset-1.19-golang security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2892?
RHSA-2024:2892 is classified as important due to a denial of service vulnerability in the Go programming language.
How do I fix RHSA-2024:2892?
To fix RHSA-2024:2892, update to the specified package version 1.19-golang-1.19.13-7.el7_9 or higher.
What products are affected by RHSA-2024:2892?
RHSA-2024:2892 affects multiple Red Hat Developer Tools packages across various RHEL environments.
Is there a workaround for RHSA-2024:2892?
There are no known workarounds for RHSA-2024:2892; applying the security update is the recommended action.
What is CVE-2023-45288 related to RHSA-2024:2892?
CVE-2023-45288 describes a vulnerability in the Go language's net/http and x/net/http2 packages that allows for a denial of service attack.