golang-1.20.12-2.el9_3
エラータID: AXSA:2024-7630:02
リリース日:
2024/03/25 Monday - 14:23
題名:
golang-1.20.12-2.el9_3
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Go の RSA 暗号化 / 復号化の処理には、メモリリークの問題が
あるため、リモートの攻撃者により、サービス拒否攻撃 (メモリ
枯渇) を可能とする脆弱性が存在します。(CVE-2024-1394)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2024-1394
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey and ctx. That function uses named return parameters to free pkey and ctx if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey and ctx will be nil inside the deferred function that should free them.
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey and ctx. That function uses named return parameters to free pkey and ctx if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey and ctx will be nil inside the deferred function that should free them.
追加情報:
N/A
ダウンロード:
SRPMS
- golang-1.20.12-2.el9_3.src.rpm
MD5: 4674826298dcc8d8004783adfb68ecaa
SHA-256: 25d2d88596ea75eeac491b7b8cb15efb904f8e7716ff5ffc443d9dc86abdf5da
Size: 24.75 MB
Asianux Server 9 for x86_64
- golang-1.20.12-2.el9_3.x86_64.rpm
MD5: 489730c87dbbdf90c5bf2be0724a489c
SHA-256: fef4cf2df37b5b95bcf40be2da57c4433694a0704c0fbf489d4d01931f5d0e4e
Size: 608.10 kB - golang-bin-1.20.12-2.el9_3.x86_64.rpm
MD5: da769387356e6601de2d117985fdae53
SHA-256: 7737ee93201c36efee4ce9f5f54e8e37b6ec84f0d39d60e5e69f3b44307b6406
Size: 58.00 MB - golang-docs-1.20.12-2.el9_3.noarch.rpm
MD5: 321d7257396318f7f8196095d241af33
SHA-256: 39a26791fb6fa9dcea4faf9a269b3ea775609990a825242a8fbe48a7e1b05f1a
Size: 104.65 kB - golang-misc-1.20.12-2.el9_3.noarch.rpm
MD5: e77d3d72ee980ce61b81a0c7993506ef
SHA-256: 2e8c40744c2da83fcd9ebd8eb68c73679690e255285e50fe627530ca3bb6fa9c
Size: 303.18 kB - golang-src-1.20.12-2.el9_3.noarch.rpm
MD5: 5435aab47dd1f9cbf773afe9e3002b0b
SHA-256: 1c3f571ea3df12ae8342f4f7b6812ea727ede0e7ab13ec9cff9d0406b335d2d4
Size: 11.64 MB - golang-tests-1.20.12-2.el9_3.noarch.rpm
MD5: fd060b56d590c3d3b064fd002f58fc0e
SHA-256: 1bdf949b2814f281a2cddff5f220b3a7803a1cc04931417db3c0b7009f52496e
Size: 9.28 MB - go-toolset-1.20.12-2.el9_3.x86_64.rpm
MD5: 631ab7e119b575733192d89202837794
SHA-256: 16a56085e1d0de88dab29e640bf8bfd47d58c66b45560183812d07cb16da77e1
Size: 8.85 kB