| Summary: | golang new security issues CVE-2022-2377[23] and CVE-2022-23806 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, bruno, davidwhodgins, sysadmin-bugs, tarazed25 |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | golang-1.17.5-1.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2022-03-04 19:25:53 CET
David Walser
2022-03-04 19:26:09 CET
Whiteboard:
(none) =>
MGA8TOO cauldron and mg8 updated with golang-1.17.7-1.mga8.src.rpm Version:
Cauldron =>
8 golang-tests-1.17.7-1.mga8 golang-1.17.7-1.mga8 golang-misc-1.17.7-1.mga8 golang-docs-1.17.7-1.mga8 golang-src-1.17.7-1.mga8 golang-shared-1.17.7-1.mga8 golang-bin-1.17.7-1.mga8 from golang-1.17.7-1.mga8.src.rpm Status comment:
Fixed upstream in 1.17.7 =>
(none) mageia8, x86_64
The seven packages updated cleanly.
To test, rebuilt docker in user directory.
Installed mgarepo and bm.
$ mgarepo co docker
$ cd docker
$ bm -s
creating package list
processing package %{origname}-%{moby_version}-%mkrel 3
building source package
succeeded!
$ ll
total 24
drwxr-xr-x 2 lcl lcl 4096 Mar 5 08:23 BUILD/
drwxr-xr-x 2 lcl lcl 4096 Mar 5 08:23 BUILDROOT/
drwxr-xr-x 2 lcl lcl 4096 Mar 5 08:23 RPMS/
drwxr-xr-x 2 lcl lcl 4096 Mar 5 08:22 SOURCES/
drwxr-xr-x 2 lcl lcl 4096 Mar 5 08:23 SPECS/
drwxr-xr-x 2 lcl lcl 4096 Mar 5 08:23 SRPMS/
$ sudo urpmi --buildrequires SPECS/docker.spec
[...]
66MB of additional disk space will be used.
12MB of packages will be retrieved.
Proceed with the installation of the 46 packages? (Y/n)
OK so far.
$ bm
creating package list
processing package %{origname}-%{moby_version}-%mkrel 3
building source and binary packages
<few minutes wait>
succeeded!
$ ls RPMS/x86_64
docker-20.10.9-3.mga8.x86_64.rpm
docker-devel-20.10.9-3.mga8.x86_64.rpm
docker-fish-completion-20.10.9-3.mga8.x86_64.rpm
docker-logrotate-20.10.9-3.mga8.x86_64.rpm
docker-nano-20.10.9-3.mga8.x86_64.rpm
docker-zsh-completion-20.10.9-3.mga8.x86_64.rpm
golang is working.CC:
(none) =>
tarazed25 And final check: $ rpm -q docker docker-20.10.9-3.mga8 Validating. Keywords:
(none) =>
validated_update
Dave Hodgins
2022-03-07 20:55:43 CET
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0091.html Resolution:
(none) =>
FIXED |