golang-1.23.9-1.el9_6
エラータID: AXSA:2025-10534:02
リリース日:
2025/07/22 Tuesday - 15:38
題名:
golang-1.23.9-1.el9_6
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- Golang の net/http ライブラリには、bare LF コードを許可して
しまう問題があるため、リモートの攻撃者により、チャンクデータを
介して、 HTTP リクエストスマグリング攻撃を可能とする脆弱性が
存在します。(CVE-2025-22871)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2025-22871
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
追加情報:
N/A
ダウンロード:
SRPMS
- golang-1.23.9-1.el9_6.src.rpm
MD5: 24f448632058795481c17f001463af18
SHA-256: ddc3a37f96fbe6a29c09f9ec1e1b73e36b28045801d8b3304ad73accdffd4607
Size: 29.24 MB
Asianux Server 9 for x86_64
- golang-1.23.9-1.el9_6.x86_64.rpm
MD5: 938f20e7416348524e4684c00dff7fc0
SHA-256: c9beed2e937d9740a8bdb0d9c85d54d9b4118eb2409ac8fa84e70522d3a1f4ce
Size: 673.85 kB - golang-bin-1.23.9-1.el9_6.x86_64.rpm
MD5: 5ba2dac2c670bbe5cbb80d97ee52f83b
SHA-256: 5186a1c0b582414fb182dcf38b6f258a36d1974a44b94a62dd4caf4901b8b1a4
Size: 63.13 MB - golang-docs-1.23.9-1.el9_6.noarch.rpm
MD5: 3889ae336165886f332a287da076ad30
SHA-256: 696aa8964b049287b1f576818e5fd364657e3ed6aaf580d6def62e826770480d
Size: 109.94 kB - golang-misc-1.23.9-1.el9_6.noarch.rpm
MD5: 0342afecac164a348470c18f6640d62b
SHA-256: 235362428f810f565a8062ef72699d593af647bd100c689c2b656ad70fc59ab5
Size: 49.25 kB - golang-race-1.23.9-1.el9_6.x86_64.rpm
MD5: 2e4edb92bf6f0863695db678fd81f13c
SHA-256: ab7522926a07add05c446b5f70bbf7260186653684d11ab5a6d0c725035e4006
Size: 203.90 kB - golang-src-1.23.9-1.el9_6.noarch.rpm
MD5: 85310492c37b3a52894220f57c83f308
SHA-256: d540b5e0e4f4e8e67d75c57920276444e1749b0eafced714d8a978a3b271217e
Size: 10.62 MB - golang-tests-1.23.9-1.el9_6.noarch.rpm
MD5: 1cffec5667fb704a85fae8a6cdae3c33
SHA-256: 94217fbfa3f8636d9036efa73f980244757ef68e2581f527cb17293840f1b354
Size: 9.62 MB - go-toolset-1.23.9-1.el9_6.x86_64.rpm
MD5: 9a0e1785b5b3cb4cab4b4513e29bd60d
SHA-256: efb6b6b603c0723f072d582a0d6ecbf690c00b625d9419caba1cf9d92c4651e3
Size: 9.75 kB