Lucene search

K
osvGoogleOSV:RLSA-2022:5337
HistoryJun 28, 2022 - 10:54 a.m.

Moderate: go-toolset:rhel8 security and bug fix update

2022-06-2810:54:21
Google
osv.dev
8
go toolset
rhel8
security
bug fix
update
golang
cve-2022-24675
cve-2022-28327
cve-2022-29526
bz#2091077

AI Score

7.2

Confidence

High

EPSS

0.005

Percentile

77.7%

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • golang: encoding/pem: fix stack overflow in Decode (CVE-2022-24675)

  • golang: crypto/elliptic: panic caused by oversized scalar (CVE-2022-28327)

  • golang: syscall: faccessat checks wrong group (CVE-2022-29526)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Update to Go 1.17.10 (BZ#2091077)

AI Score

7.2

Confidence

High

EPSS

0.005

Percentile

77.7%