MGASA-2024-0376 - Updated golang packages fix security vulnerabilities

Publication date: 27 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0376.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-34155,
     CVE-2024-34156,
     CVE-2024-34158

Calling any of the Parse functions on Go source code which contains
deeply nested literals can cause a panic due to stack exhaustion.
CVE-2024-34155
Calling Decoder.Decode on a message which contains deeply nested
structures can cause a panic due to stack exhaustion CVE-2024-34156
Calling Parse on a "// +build" build tag line with deeply nested
expressions can cause a panic due to stack exhaustion.CVE-2024-34158

References:
- https://bugs.mageia.org/show_bug.cgi?id=33526
- https://www.openwall.com/lists/oss-security/2024/09/05/1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34155
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34158

SRPMS:
- 9/core/golang-1.22.9-1.mga9

Mageia 2024-0376: golang Security Advisory Updates

Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion

Summary

Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion. CVE-2024-34155 Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34156 Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.CVE-2024-34158

References

- https://bugs.mageia.org/show_bug.cgi?id=33526

- https://www.openwall.com/lists/oss-security/2024/09/05/1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34155

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34158

Resolution

MGASA-2024-0376 - Updated golang packages fix security vulnerabilities

SRPMS

- 9/core/golang-1.22.9-1.mga9

Severity
Publication date: 27 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0376.html
Type: security
CVE: CVE-2024-34155, CVE-2024-34156, CVE-2024-34158

Related News