FlawAtlas
Search the atlas
SUSE-SU-2023:1792-1 Not scored

Security update for go1.19

This update for go1.19 fixes the following issues: Update to 1.19.8 * CVE-2023-24534: security: net/http, net/textproto: denial of service from excessive memory allocation (bsc#1210127) * CVE-2023-24536: security: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (bsc#1210128) * CVE-2023-24537: security: go/parser: infinite loop in parsing (bsc#1210129) * CVE-2023-24538: security: html/template: backticks not treated as string delimiters (bsc#1210130) * cmd/go: timeout on darwin-amd64-race builder * runtime/pprof: TestLabelSystemstack due to sample with no location * internal/testpty: fails on some Linux machines due to incorrect error handling * cmd/link: linker fails on linux/amd64 when gcc's lto options are used * cmd/link/internal/arm: off-by-one error in trampoline phase call reachability calculation * time: time zone lookup using extend string makes wrong start time for non-DST zones * runtime: crash on linux-ppc64le

Exploit probability Not scored
Published April 6, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 go1.19
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS go1.19
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS go1.19
SUSE:Linux Enterprise Module for Development Tools 15 SP4 go1.19
SUSE:Linux Enterprise Real Time 15 SP3 go1.19
SUSE:Linux Enterprise Server 15 SP3-LTSS go1.19
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 go1.19
openSUSE:Leap 15.4 go1.19

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:1792-1

This update for go1.19 fixes the following issues: Update to 1.19.8 * CVE-2023-24534: security: net/http, net/textproto: denial of service from excessive memory allocation (bsc#1210127) * CVE-2023-24536: security: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (bsc#1210128) * CVE-2023-24537: security: go/parser: infinite loop in parsing (bsc#1210129) * CVE-2023-24538: security: html/template: backticks not treated as string delimiters (bsc#1210130) * cmd/go: timeout on darwin-amd64-race builder * runtime/pprof: TestLabelSystemstack due to sample with no location * internal/testpty: fails on some Linux machines due to incorrect error handling * cmd/link: linker fails on linux/amd64 when gcc's lto options are used * cmd/link/internal/arm: off-by-one error in trampoline phase call reachability calculation * time: time zone lookup using extend string makes wrong start time for non-DST zones * runtime: crash on linux-ppc64le

View original source

05 / REFERENCES

Further evidence