Security update for go1.18
This update for go1.18 fixes the following issues: Updated to version 1.18.7 (bsc#1193742): - CVE-2022-41715: Fixed memory exhaustion in regexp/syntax (bsc#1204023). - CVE-2022-2879: Fixed unbounded memory consumption when reading headers in archive/tar (bsc#1204024). - CVE-2022-2880: Fixed ReverseProxy forwarding unparseable query parameters (bsc#1204025).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for go1.18 fixes the following issues: Updated to version 1.18.7 (bsc#1193742): - CVE-2022-41715: Fixed memory exhaustion in regexp/syntax (bsc#1204023). - CVE-2022-2879: Fixed unbounded memory consumption when reading headers in archive/tar (bsc#1204024). - CVE-2022-2880: Fixed ReverseProxy forwarding unparseable query parameters (bsc#1204025).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1193742
- https://bugzilla.suse.com/1204023
- https://bugzilla.suse.com/1204024
- https://bugzilla.suse.com/1204025
- https://www.suse.com/security/cve/CVE-2022-2879
- https://www.suse.com/security/cve/CVE-2022-2880
- https://www.suse.com/security/cve/CVE-2022-41715
- https://www.suse.com/support/update/announcement/2022/suse-su-20223668-1/