Bug 31886 - golang new security issues CVE-2023-24539, CVE-2023-24540, and CVE-2023-29400
Summary: golang new security issues CVE-2023-24539, CVE-2023-24540, and CVE-2023-29400
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-05-06 23:52 CEST by David Walser
Modified: 2023-07-13 07:18 CEST (History)
5 users (show)

See Also:
Source RPM: golang-1.20.3-2.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-05-06 23:52:11 CEST
Go 1.20.4 and Go 1.19.9 have been released on May 2, fixing security issues:
https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU

SUSE has issued an advisory for this on May 5:
https://lists.suse.com/pipermail/sle-security-updates/2023-May/014738.html
David Walser 2023-05-06 23:52:26 CEST

Status comment: (none) => Fixed upstream in 1.19.9 and 1.20.4
Whiteboard: (none) => MGA8TOO

Bruno Cornec 2023-05-09 10:30:18 CEST

Status: NEW => ASSIGNED

Comment 1 Bruno Cornec 2023-05-09 10:40:49 CEST
1.20.4 on its way to cauldron.

Status comment: Fixed upstream in 1.19.9 and 1.20.4 => Fixed upstream in 1.19.9
Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8

Comment 2 Bruno Cornec 2023-05-09 20:50:20 CEST
1.19.9 on its way to mga8.

Assignee: bruno => qa-bugs
Status comment: Fixed upstream in 1.19.9 => (none)

Comment 3 David Walser 2023-05-10 04:19:17 CEST
golang-1.19.9-1.mga8
golang-tests-1.19.9-1.mga8
golang-misc-1.19.9-1.mga8
golang-docs-1.19.9-1.mga8
golang-src-1.19.9-1.mga8
golang-shared-1.19.9-1.mga8
golang-bin-1.19.9-1.mga8

from golang-1.19.9-1.mga8.src.rpm

CC: (none) => bruno

Comment 4 Len Lawrence 2023-05-14 12:39:20 CEST
mga8, x64
Smooth update.
Using a rebuild of docker to test the compiler.
Removed all old files from ~/docker.

$ mgarepo co docker
$ bm -s
$ sudo urpmi --buildrequires SPECS/docker.spec
Long list of packages - indicates that this is the first time for this system.
$ bm -l
......
succeeded!
Checked to see that the built version of docker coincided with the already installed docker.  OK.

Sending this on.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => tarazed25

Comment 5 Thomas Andrews 2023-05-16 00:05:15 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2023-05-16 19:16:37 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 6 Mageia Robot 2023-05-16 21:19:15 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0169.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Drake Denise 2023-06-12 11:49:09 CEST

CC: (none) => severalforecabin

kiri cowell 2023-07-13 06:23:52 CEST

CC: (none) => kiricowell97

Thomas Backlund 2023-07-13 07:18:39 CEST

CC: kiricowell97, severalforecabin => (none)


Note You need to log in before you can comment on or make changes to this bug.