FlawAtlas
Search the atlas
SUSE-SU-2023:0869-1 Not scored

Security update for go1.18

This update for go1.18 fixes the following issues: - CVE-2022-41723: Fixed a quadratic complexity in HPACK decoding in net/http (bsc#1208270). - CVE-2022-41724: Fixed a denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208271). - CVE-2022-41725: Fixed a panic with large handshake records in crypto/tls (bsc#1208272). The following non-security bug was fixed: - Fixed PTF ref:_00D1igLOd._5005qM0AP4:ref SG#65262 (bsc#1208491).

Exploit probability Not scored
Published March 22, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 go1.18
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS go1.18
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS go1.18
SUSE:Linux Enterprise Module for Development Tools 15 SP4 go1.18
SUSE:Linux Enterprise Real Time 15 SP3 go1.18
SUSE:Linux Enterprise Server 15 SP3-LTSS go1.18
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 go1.18
openSUSE:Leap 15.4 go1.18

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:0869-1

This update for go1.18 fixes the following issues: - CVE-2022-41723: Fixed a quadratic complexity in HPACK decoding in net/http (bsc#1208270). - CVE-2022-41724: Fixed a denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208271). - CVE-2022-41725: Fixed a panic with large handshake records in crypto/tls (bsc#1208272). The following non-security bug was fixed: - Fixed PTF ref:_00D1igLOd._5005qM0AP4:ref SG#65262 (bsc#1208491).

View original source

05 / REFERENCES

Further evidence