RLSA-2022:1819 --- golangID: oval:org.secpod.oval:def:4500895 | Date: (C)2023-04-03 (M)2023-12-11 |
Class: PATCH | Family: unix |
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix: * golang: Command-line arguments may overwrite global data * golang: archive/zip: malformed archive may cause panic or memory exhaustion * golang: debug/macho: invalid dynamic symbol table command can cause panic * golang: archive/zip: Reader.Open panics on empty string * golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString * golang: cmd/go: misinterpretation of branch names can lead to incorrect access control * golang: crypto/elliptic IsOnCurve returns true for invalid field elements For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.
Product: |
golang |
delve |
go-toolset |