Bug 30323 - golang-x-crypto new security issues CVE-2021-43565 and CVE-2022-27191
Summary: golang-x-crypto new security issues CVE-2021-43565 and CVE-2022-27191
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Guillaume Rousse
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-04-22 20:19 CEST by David Walser
Modified: 2024-01-12 10:24 CET (History)
4 users (show)

See Also:
Source RPM: golang-x-crypto-0-3.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-04-22 20:19:36 CEST
Fedora has issued an advisory on April 21:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HHGBEGJ54DZZGTXFUQNS7ZIG3E624YAF/

Mageia 8 is also affected.
David Walser 2022-04-22 20:19:51 CEST

CC: (none) => joequant
Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Lécureuil 2022-04-25 09:44:48 CEST
already fixed in cauldron

Whiteboard: MGA8TOO => (none)
CC: (none) => mageia
Version: Cauldron => 8

Comment 2 David Walser 2022-05-02 22:32:53 CEST
Apparently docker-containerd needs to be rebuilt after fixing this:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QEUMK3PSJ5NWTNRYD4NCKCI2QFWD3MIU/
Comment 3 David Walser 2022-05-02 22:33:29 CEST
(In reply to David Walser from comment #2)
> Apparently docker-containerd needs to be rebuilt after fixing this:
> https://lists.fedoraproject.org/archives/list/package-announce@lists.
> fedoraproject.org/thread/QEUMK3PSJ5NWTNRYD4NCKCI2QFWD3MIU/

and so does golang-github-envoyproxy-protoc-gen-validate:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JEX3J6S5PUUNLWYVJJLRZR5OLVQSEG63/
Comment 4 David Walser 2022-05-02 22:35:17 CEST
and *possibly* golang-github-grpc-ecosystem-gateway (Fedora's is 2.x):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ROCG2IVQDIHQBGYEHNBEBAIBBAJPCP66/
Comment 8 David Walser 2022-05-04 18:46:15 CEST
SUSE has issued an advisory on May 3:
https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html

Their docker-containerd was affected by this and another golang-x-crypto issue.

Summary: golang-x-crypto new security issue CVE-2022-27191 => golang-x-crypto new security issues CVE-2021-43565 and CVE-2022-27191

Comment 9 David Walser 2022-05-07 21:26:32 CEST
(In reply to David Walser from comment #7)
> and golang-x-perf:
> https://lists.fedoraproject.org/archives/list/package-announce@lists.
> fedoraproject.org/thread/NY243XWDC6FN2CYDWS6UTH23QFK7O4FB/

and golang-x-exp:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/CSK2WSATFKWMIL25LDCZSLZODLXQ47H4/
Comment 10 Guillaume Rousse 2022-05-14 22:23:50 CEST
Updating to a new git snapshot requires new dependencies, such as golang-x-term, which were not present in Mageia 8. What is the procedure for introducing new packages in updates ?
Comment 11 David Walser 2022-05-14 22:42:13 CEST
svn cp svn+ssh://svn.mageia.org/svn/packages/cauldron/golang-x-term svn+ssh://svn.mageia.org/svn/packages/updates/8/ -m 'backport golang-x-term dependency for golang-x-crypto update'

Something like that.  Then you can mgarepo co it and set the release tag back to 1 if it isn't already.
Comment 12 David Walser 2022-05-15 15:23:54 CEST
Built so far by Guillaume:
golang-x-term-devel-0-1.mga8
golang-x-crypto-devel-0-0.31.1.mga8

from SRPMS:
golang-x-term-0-1.mga8.src.rpm
golang-x-crypto-0-0.31.1.mga8.src.rpm


Possibly needed rebuilds still pending.
Comment 13 David Walser 2022-05-16 20:27:30 CEST
(In reply to David Walser from comment #8)
> SUSE has issued an advisory on May 3:
> https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html
> 
> Their docker-containerd was affected by this and another golang-x-crypto
> issue.

Equivalent openSUSE advisory:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GLQWASKPS7Q4NRXKRDNAWDTE3NI3CGU3/
David Walser 2022-12-12 17:48:12 CET

Blocks: (none) => 31268

Comment 14 Bruno Cornec 2022-12-30 23:32:44 CET
(In reply to David Walser from comment #2)
> Apparently docker-containerd needs to be rebuilt after fixing this:
> https://lists.fedoraproject.org/archives/list/package-announce@lists.
> fedoraproject.org/thread/QEUMK3PSJ5NWTNRYD4NCKCI2QFWD3MIU/

For me docker-containerd is not concerned as patches are related to the ssh subsystem which is not relevant to docker-containerd.

CC: (none) => bruno

Comment 15 David Walser 2023-06-20 14:00:03 CEST
Debian-LTS has issued an advisory on June 16:
https://www.debian.org/lts/security/2023/dla-3455

It lists some older issues that might affect this.
Bruno Cornec 2023-07-25 16:59:20 CEST

Blocks: 31268 => (none)

Comment 16 David Walser 2023-07-26 03:53:12 CEST
(In reply to David Walser from comment #13)
> (In reply to David Walser from comment #8)
> > SUSE has issued an advisory on May 3:
> > https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html
> > 
> > Their docker-containerd was affected by this and another golang-x-crypto
> > issue.
> 
> Equivalent openSUSE advisory:
> https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.
> org/thread/GLQWASKPS7Q4NRXKRDNAWDTE3NI3CGU3/

Bruno,

What about this one w.r.t docker-containerd?
Comment 17 Bruno Cornec 2023-07-26 11:48:58 CEST
(In reply to David Walser from comment #16)
> (In reply to David Walser from comment #13)
> > (In reply to David Walser from comment #8)
> > > SUSE has issued an advisory on May 3:
> > > https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html
> > > 
> > > Their docker-containerd was affected by this and another golang-x-crypto
> > > issue.
> > 
> > Equivalent openSUSE advisory:
> > https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.
> > org/thread/GLQWASKPS7Q4NRXKRDNAWDTE3NI3CGU3/
> 
> Bruno,
> 
> What about this one w.r.t docker-containerd?

My comment has not changed since comment 14:
For me docker-containerd is not concerned as patches are related to the ssh subsystem which is not relevant to docker-containerd.
Comment 18 Nicolas Salguero 2024-01-12 10:24:10 CET
Mageia 8 EOL

CC: (none) => nicolas.salguero
Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.