RHSA-2024:4146: Important: golang security update
Important: golang security update
Other sources
The golang packages provide the Go programming language compiler.Security Fix(es): golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288) golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4146?
The severity of RHSA-2024:4146 is classified as Important.
How do I fix RHSA-2024:4146?
To fix RHSA-2024:4146, update the golang packages to version 1.19.13-7.el9_2.
What does the RHSA-2024:4146 vulnerability affect?
RHSA-2024:4146 affects the golang packages that provide the Go programming language compiler.
What security issues are addressed in RHSA-2024:4146?
RHSA-2024:4146 addresses a denial of service vulnerability caused by an unlimited number of CONTINUATION frames (CVE-2023-45288).
Are there any specific packages affected by RHSA-2024:4146?
Yes, specific affected packages include golang, golang-bin, golang-docs, and several others all needing the update.