| Summary: | golang new security issues CVE-2021-4471[67] | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, bruno, davidwhodgins, pauldupont1120, sysadmin-bugs, tarazed25 |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | golang-1.17.3-1.mga8.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 1.17.5 | ||
|
Description
David Walser
2021-12-23 17:45:47 CET
David Walser
2021-12-23 17:46:04 CET
Status comment:
(none) =>
Fixed upstream in 1.17.5 openSUSE has issued an advisory for this today (December 23): https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LSVRDOAVYBVEWAKYWYYNOIQSYE4FHHAJ/
Bruno Cornec
2021-12-23 21:53:42 CET
Status:
NEW =>
ASSIGNED golang 1.17.5 pushed to cauldron. CC:
(none) =>
bruno
David Walser
2021-12-23 23:18:37 CET
Whiteboard:
MGA8TOO =>
(none) Same version pushed to mga8 updates_testing Assignee:
bruno =>
qa-bugs golang-docs-1.17.5-1.mga8 golang-misc-1.17.5-1.mga8 golang-1.17.5-1.mga8 golang-tests-1.17.5-1.mga8 golang-src-1.17.5-1.mga8 golang-race-1.17.5-1.mga8 golang-shared-1.17.5-1.mga8 golang-bin-1.17.5-1.mga8 from golang-1.17.5-1.mga8.src.rpm mga8, x64
So soon?
Updated cleanly via qarepo.
Trying docker build as a test:
$ cd docker
$ rm -rf docker
$ mgarepo co docker
$ cd docker
$ bm -s
creating package list
processing package %{origname}-%{moby_version}-%mkrel 3
building source package
succeeded!
$ sudo urpmi --buildrequires SPECS/docker.spec
warning: Macro expanded in comment on line 43: %{shortcommit_moby}
warning: line 119: It's not recommended to have unversioned Obsoletes: Obsoletes: docker-swarm
warning: line 121: It's not recommended to have unversioned Obsoletes: Obsoletes: docker-vim
$ bm
creating package list
processing package %{origname}-%{moby_version}-%mkrel 3
building source and binary packages
succeeded!
$ ls RPMS/x86_64
docker-20.10.9-3.mga8.x86_64.rpm
docker-devel-20.10.9-3.mga8.x86_64.rpm
docker-fish-completion-20.10.9-3.mga8.x86_64.rpm
docker-logrotate-20.10.9-3.mga8.x86_64.rpm
docker-nano-20.10.9-3.mga8.x86_64.rpm
docker-zsh-completion-20.10.9-3.mga8.x86_64.rpm
OK for 64-bits.CC:
(none) =>
tarazed25 $ rpm -q golang golang-1.17.5-1.mga8 Validating. CC:
(none) =>
andrewsfarm, sysadmin-bugs
Dave Hodgins
2021-12-25 23:34:56 CET
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0587.html Status:
ASSIGNED =>
RESOLVED Great information. It took me a while to fully understand it https://tunnel-rush.co/ CC:
(none) =>
pauldupont1120 |