grafana-9.2.10-8.el8_9.ML.1
エラータID: AXSA:2024-7660:04
リリース日:
2024/04/05 Friday - 17:53
題名:
grafana-9.2.10-8.el8_9.ML.1
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Go の RSA 暗号化 / 復号化の処理には、メモリリークの
問題があるため、リモートの攻撃者により、サービス拒否
攻撃 (メモリ枯渇) を可能とする脆弱性が存在します。
(CVE-2024-1394)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2024-1394
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.
追加情報:
N/A
ダウンロード:
SRPMS
- grafana-9.2.10-8.el8_9.ML.1.src.rpm
MD5: 1d4d6e1f80af97aaea6934e8f7557306
SHA-256: b033d23f619cef8617ae0d889eeffe60842fa561a542b68835c4ff4eb3a45b10
Size: 321.66 MB
Asianux Server 8 for x86_64
- grafana-9.2.10-8.el8_9.ML.1.x86_64.rpm
MD5: 0cd6db6076ecdc263863189655920733
SHA-256: bfd0b31a264dc98c8f54f85f09c422aaa143190c87516f7a4c8a288106d3fc42
Size: 75.99 MB