| Summary: | golang new security issues CVE-2022-1705 CVE-2022-1962 CVE-2022-28131 CVE-2022-3063[01235] CVE-2022-32148 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, bruno, davidwhodgins, sysadmin-bugs, tarazed25 |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | golang-1.18.3-1.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2022-07-15 19:44:37 CEST
David Walser
2022-07-15 19:44:57 CEST
Status comment:
(none) =>
Fixed upstream in 1.17.12 and 1.18.4 Updated packages uploaded by Bruno for Mageia 8 and Cauldron. golang-docs-1.17.12-1.mga8 golang-misc-1.17.12-1.mga8 golang-1.17.12-1.mga8 golang-tests-1.17.12-1.mga8 golang-src-1.17.12-1.mga8 golang-shared-1.17.12-1.mga8 golang-bin-1.17.12-1.mga8 from golang-1.17.12-1.mga8.src.rpm CC:
(none) =>
bruno Cauldron, x64 Had a look for the Cauldron version using "cauldron" in qarepo but it could not find the packages. mga8, x64 Smooth update. Local build of docker succeeded. $ ls RPMS/x86_64 docker-20.10.16-1.mga8.x86_64.rpm docker-devel-20.10.16-1.mga8.x86_64.rpm docker-fish-completion-20.10.16-1.mga8.x86_64.rpm docker-logrotate-20.10.16-1.mga8.x86_64.rpm docker-nano-20.10.16-1.mga8.x86_64.rpm docker-zsh-completion-20.10.16-1.mga8.x86_64.rpm Compare with the installed version: $ rpm -q docker docker-20.10.14-3.mga8 Looks good for 64-bits. Whiteboard:
(none) =>
MGA8-64-OK @Len: You test seems to be for the wrong bug. It better suits bug Bug 30422. Removing MGA(-64-OK. Whiteboard:
MGA8-64-OK =>
(none)
Thomas Backlund
2022-07-16 11:01:52 CEST
Version:
Cauldron =>
8 @sturmvogel regarding comment 3: Sorry, I should have been more specific. The rebuild of docker to exercise golang was suggested long ago. With terminal logging enabled it is evident that golang is working hard. These were the packages installed, alongside 42 other golang-related packages: $ rpm -qa | grep 1.17.12-1 golang-1.17.12-1.mga8 golang-docs-1.17.12-1.mga8 golang-bin-1.17.12-1.mga8 golang-misc-1.17.12-1.mga8 golang-src-1.17.12-1.mga8 golang-tests-1.17.12-1.mga8 golang-shared-1.17.12-1.mga8 Again, apologies. And, @Thomas - yes, thanks for the correction - forgot where I was. Ah ok, understood Len. So your MGA8-64-OK is valid then? Yes, I hope so. Putting it back. Whiteboard:
(none) =>
MGA8-64-OK Glad you got things straightened out. Validating. Keywords:
(none) =>
validated_update
Dave Hodgins
2022-07-16 17:23:35 CEST
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0262.html Resolution:
(none) =>
FIXED |