CVE-2025-22870 was announced here: https://www.openwall.com/lists/oss-security/2025/03/07/2
Whiteboard: (none) => MGA9TOOSource RPM: (none) => golang-1.23.6-1.mga10.src.rpm, golang-1.22.12-1.mga9.src.rpmStatus comment: (none) => Fixed upstream in 1.23.7, version 1.22 not fixed for the momentCVE: (none) => CVE-2025-22870
Note: Fixed upstream in 1.23.7 (Cauldron), version 1.22 5Mageia 9) not fixed for the moment. Different packagers handle golang, so assigning globally.
Assignee: bugsquad => pkg-bugs
Version: Cauldron => 9Source RPM: golang-1.23.6-1.mga10.src.rpm, golang-1.22.12-1.mga9.src.rpm => golang-1.22.12-1.mga9.src.rpmWhiteboard: MGA9TOO => (none)
CVE-2025-22871 was announced here: https://www.openwall.com/lists/oss-security/2025/04/04/4
Whiteboard: (none) => MGA9TOOSource RPM: golang-1.22.12-1.mga9.src.rpm => golang-1.23.7-1.mga10.src.rpm, golang-1.22.12-1.mga9.src.rpmSummary: golang new security issue CVE-2025-22870 => golang new security issue CVE-2025-2287[01]Version: 9 => CauldronStatus comment: Fixed upstream in 1.23.7, version 1.22 not fixed for the moment => Fixed upstream in 1.23.8, version 1.22 not fixed for the momentCVE: CVE-2025-22870 => CVE-2025-22870, CVE-2025-22871
Source RPM: golang-1.23.7-1.mga10.src.rpm, golang-1.22.12-1.mga9.src.rpm => golang-1.22.12-1.mga9.src.rpmWhiteboard: MGA9TOO => (none)Version: Cauldron => 9
Why not build golang-1.23.7-1 ? Build without issues for mageia 9
(In reply to katnatek from comment #3) > Why not build golang-1.23.7-1 ? > Build without issues for mageia 9 1.23.8-1 is the version I build
Fedora has issued an advisory on April 15: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FFNTP3P4URUREHKSWZQWIJPIXGRCFHUI/
Assignee: pkg-bugs => j.alberto.vcSee Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=33973
RPMS: golang-1.23.8-1.mga9 golang-bin-1.23.8-1.mga9 golang-docs-1.23.8-1.mga9 golang-misc-1.23.8-1.mga9 golang-shared-1.23.8-1.mga9 golang-src-1.23.8-1.mga9 golang-tests-1.23.8-1.mga9 SRPM: golang-1.23.8-1.mga9
Assignee: j.alberto.vc => qa-bugs
Used to build docker without issues
Keywords: (none) => advisoryWhiteboard: (none) => MGA9-64-OK
Whiteboard: MGA9-64-OK => MGA9-64-OK,MGA9-32-OK
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0175.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED