https://seclists.org/oss-sec/2024/q1/197: 5 CVEs fixed in Go 1.22.1 and Go 1.21.8, 1 CVE fixed in google.golang.org/protobuf
Published Mar 8, 2024
·Updated
Affected Software
2 affected components
Google Go
Google Protobuf
Frequently Asked Questions
1
What is the severity of CVE-2024-0303?
CVE-2024-0303 has a severity rating of medium.
2
How do I fix CVE-2024-0303?
To fix CVE-2024-0303, upgrade to Google Go version 1.22.1 or later.
3
What vulnerability does CVE-2024-0304 address?
CVE-2024-0304 addresses a potential denial of service vulnerability in Google Go.
4
Which versions of Google Protobuf are affected by CVE-2024-0305?
CVE-2024-0305 affects all versions of Google Protobuf prior to the fix issued in the latest update.
5
Are there any performance impacts noted for the fixed vulnerabilities in Google Go?
The fixed vulnerabilities in Google Go have not reported any significant performance impacts.