Mageia 2024-0376: golang Security Advisory Updates
Summary
Calling any of the Parse functions on Go source code which contains
deeply nested literals can cause a panic due to stack exhaustion.
CVE-2024-34155
Calling Decoder.Decode on a message which contains deeply nested
structures can cause a panic due to stack exhaustion CVE-2024-34156
Calling Parse on a "// +build" build tag line with deeply nested
expressions can cause a panic due to stack exhaustion.CVE-2024-34158
References
- https://bugs.mageia.org/show_bug.cgi?id=33526
- https://www.openwall.com/lists/oss-security/2024/09/05/1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34155
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34158
Resolution
MGASA-2024-0376 - Updated golang packages fix security vulnerabilities
SRPMS
- 9/core/golang-1.22.9-1.mga9
![Dist Mageia](/images/distros/dist-mageia.jpg)