Bug 30646 - golang-x-sys new security issue CVE-2022-29526
Summary: golang-x-sys new security issue CVE-2022-29526
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Pascal Terjan
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-07-16 12:24 CEST by Marja Van Waes
Modified: 2022-07-17 22:49 CEST (History)
7 users (show)

See Also:
Source RPM: golang-x-sys-0-0.43.mga9.src.rpm
CVE:
Status comment:


Attachments

Description Marja Van Waes 2022-07-16 12:24:50 CEST
+++ This bug was initially created as a clone of Bug #30422 +++

Docker 20.10.16 has been released on May 12:
https://github.com/moby/moby/releases/tag/v20.10.16

It includes a fix for a security issue in its bundled golang-x-sys.

Mageia 8 is also affected.

=====================================================================

Docker was fixed a month ago, golang-x-sys still needs to be fixed.
Marja Van Waes 2022-07-16 12:25:20 CEST

Whiteboard: (none) => MGA8TOO

Marja Van Waes 2022-07-16 13:19:41 CEST

Depends on: 30422 => (none)
See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=30422

Comment 1 Marja Van Waes 2022-07-16 13:57:57 CEST Comment hidden (obsolete)
Comment 2 Marja Van Waes 2022-07-16 15:50:50 CEST
guillomovitch just pushed golang-x-sys-0-0.44.mga9 
thanks :-)

guillomovitch <guillomovitch> 0-0.44.mga9:
+ Revision: 1869189
- new git snapshot

I don't know how to see whether that fixes CVE-2022-29526, https://github.com/golang/sys/security/advisories is empty
Comment 3 Marja Van Waes 2022-07-16 17:53:33 CEST
But here https://github.com/golang/go/issues/52313#issuecomment-1097210431 it says:

"golang.org/x/sys/unix".Faccessat suffers from the same problem, but only on Linux kernels < 5.8.

We have kernel-5.15.50-1.mga8 and kernel-5.18.12-1.mga9, so our golang-x-sys is not (or at least no longer) affected, right??
Comment 4 David Walser 2022-07-17 20:37:43 CEST
I don't see the connection to the CVE and I'm not sure that Faccessat's issue is all that it's about.

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)

Comment 5 Marja Van Waes 2022-07-17 22:27:49 CEST
(In reply to David Walser from comment #4)
> I don't see the connection to the CVE 

Yeah, sorry, I should have said where I got that link from. It was one of the references here https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526
and the only reference to https://github.com/golang/

> and I'm not sure that Faccessat's
> issue is all that it's about.
Comment 6 David Walser 2022-07-17 22:49:11 CEST
Thanks.

Status: NEW => RESOLVED
Resolution: (none) => INVALID


Note You need to log in before you can comment on or make changes to this bug.