Security Vulnerabilities fixed in delve RHSA-2023:0446

description-logoDescription

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879) golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880) golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879) golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880) golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): Internal linking fails on ppc64le (BZ#2144545) crypto testcases fail on golang on s390x [rhel-8] (BZ#2149313) Internal linking fails on ppc64le (BZ#2144545) crypto testcases fail on golang on s390x [rhel-8] (BZ#2149313) SolutionFor details on how to apply this update, which includes the changes described in this advisory, refer to:https://access.redhat.com/articles/11258

affected-products-logoAffected Applications

delve