Oracle Linux Security Advisory ELSA-2024-8876

http://linux.oracle.com/errata/ELSA-2024-8876.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
delve-1.22.1-1.0.1.module+el8.10.0+90426+810ab996.x86_64.rpm
golang-1.22.7-1.module+el8.10.0+90426+810ab996.x86_64.rpm
golang-bin-1.22.7-1.module+el8.10.0+90426+810ab996.x86_64.rpm
golang-docs-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm
golang-misc-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm
golang-src-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm
golang-tests-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm
go-toolset-1.22.7-1.module+el8.10.0+90426+810ab996.x86_64.rpm

aarch64:
delve-1.22.1-1.0.1.module+el8.10.0+90426+810ab996.aarch64.rpm
golang-1.22.7-1.module+el8.10.0+90426+810ab996.aarch64.rpm
golang-bin-1.22.7-1.module+el8.10.0+90426+810ab996.aarch64.rpm
golang-docs-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm
golang-misc-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm
golang-src-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm
golang-tests-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm
go-toolset-1.22.7-1.module+el8.10.0+90426+810ab996.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//delve-1.22.1-1.0.1.module+el8.10.0+90426+810ab996.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates//golang-1.22.7-1.module+el8.10.0+90426+810ab996.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates//go-toolset-1.22.7-1.module+el8.10.0+90426+810ab996.src.rpm

Related CVEs:

CVE-2024-24790




Description of changes:

delve
[1.22.1-1.0.1]
- Disable DWARF compression which has issues (Alex Burmashev)

[1.22.1-1]
- Rebase to 1.22.1
- Resolves: RHEL-54307

golang
[1.22.7-1]
- Update to Go 1.22.7
- Resolves: RHEL-58223
- Resolves: RHEL-57961
- Resolves: RHEL-57847
- Resolves: RHEL-57860

[1.22.5-3]
- Update fix that loads Openssl in FIPS mode if fips==1
- Related: RHEL-52485

[1.22.5-2]
- Include fix that loads Openssl only in FIPS mode to avoid panic
- Resolves: RHEL-52485

[1.22.5-1]
- Rebase to Go1.22.5 to fix CVE-2024-24791
- Resolves: RHEL-46972

[1.22.4-1]
- Addresses CVEs-2024-24789 and CVE-2024-24790
- Resolves: RHEL-40157

[1.22.3-3]
- Update openssl backend
- Resolves: RHEL-36102

[1.22.3-2]
- Restore HashSign / HashVerify API
- Resolves: RHEL-35884

[1.22.3-1]
- Update to Go 1.22.3
- Resolves: RHEL-35884
- Resolves: RHEL-35075
- Resolves: RHEL-35632
- Resolves: RHEL-35901

[1.22.2-1]
- Rebase to 1.22.2
- Re-enable CGO
- Skip TestCrashDumpsAllThreads
- Resolves: RHEL-33157

go-toolset
[1.22.7-1]
- Update to Go 1.22.7
- Resolves: RHEL-58223
- Resolves: RHEL-57961
- Resolves: RHEL-57847
- Resolves: RHEL-57860

[1.22.5-1]
- Rebase to Go1.22.5 to fix CVE-2024-24791
- Resolves: RHEL-46972

[1.22.4-1]
- Addresses CVEs-2024-24789 and CVE-2024-24790
- Resolves: RHEL-40157

[1.22.3-1]
- Update to Go 1.22.3
- Resolves: RHEL-35884
- Resolves: RHEL-35075
- Resolves: RHEL-35632
- Resolves: RHEL-35901

[1.22.2-1]
- Update to Go 1.22.2
- Resolves: RHEL-33157


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2024-8876: go-toolset:ol8 Moderate Security Advisory Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

delve [1.22.1-1.0.1] - Disable DWARF compression which has issues (Alex Burmashev) [1.22.1-1] - Rebase to 1.22.1 - Resolves: RHEL-54307 golang [1.22.7-1] - Update to Go 1.22.7 - Resolves: RHEL-58223 - Resolves: RHEL-57961 - Resolves: RHEL-57847 - Resolves: RHEL-57860 [1.22.5-3] - Update fix that loads Openssl in FIPS mode if fips==1 - Related: RHEL-52485 [1.22.5-2] - Include fix that loads Openssl only in FIPS mode to avoid panic - Resolves: RHEL-52485 [1.22.5-1] - Rebase to Go1.22.5 to fix CVE-2024-24791 - Resolves: RHEL-46972 [1.22.4-1] - Addresses CVEs-2024-24789 and CVE-2024-24790 - Resolves: RHEL-40157 [1.22.3-3] - Update openssl backend - Resolves: RHEL-36102 [1.22.3-2] - Restore HashSign / HashVerify API - Resolves: RHEL-35884 [1.22.3-1] - Update to Go 1.22.3 - Resolves: RHEL-35884 - Resolves: RHEL-35075 - Resolves: RHEL-35632 - Resolves: RHEL-35901 [1.22.2-1] - Rebase to 1.22.2 - Re-enable CGO - Skip TestCrashDumpsAllThreads - Resolves: RHEL-33157 go-toolset [1.2...

Read the Full Advisory

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates//delve-1.22.1-1.0.1.module+el8.10.0+90426+810ab996.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//golang-1.22.7-1.module+el8.10.0+90426+810ab996.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//go-toolset-1.22.7-1.module+el8.10.0+90426+810ab996.src.rpm

x86_64

delve-1.22.1-1.0.1.module+el8.10.0+90426+810ab996.x86_64.rpm golang-1.22.7-1.module+el8.10.0+90426+810ab996.x86_64.rpm golang-bin-1.22.7-1.module+el8.10.0+90426+810ab996.x86_64.rpm golang-docs-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm golang-misc-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm golang-src-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm golang-tests-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm go-toolset-1.22.7-1.module+el8.10.0+90426+810ab996.x86_64.rpm

aarch64

delve-1.22.1-1.0.1.module+el8.10.0+90426+810ab996.aarch64.rpm golang-1.22.7-1.module+el8.10.0+90426+810ab996.aarch64.rpm golang-bin-1.22.7-1.module+el8.10.0+90426+810ab996.aarch64.rpm golang-docs-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm golang-misc-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm golang-src-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm golang-tests-1.22.7-1.module+el8.10.0+90426+810ab996.noarch.rpm go-toolset-1.22.7-1.module+el8.10.0+90426+810ab996.aarch64.rpm

i386

Severity
Related CVEs: CVE-2024-24790

Related News