Security update for go1.19
This update for go1.19 fixes the following issues: Update to 1.19.9 (bnc#1200441): - CVE-2023-24539: fixed an improper sanitization of CSS values (bnc#1211029). - CVE-2023-24540: fixed an improper handling of JavaScript whitespace (bnc#1211030). - CVE-2023-29400: fixed an improper handling of empty HTML attributes (bnc#1211031). - runtime: automatically bump RLIMIT_NOFILE on Unix - cmd/compile: inlining function that references function literals generates bad code. - cmd/compile: encoding/binary.PutUint16 sometimes doesn't write. - crypto/tls: TLSv1.3 connection fails with invalid PSK binder. - cmd/compile: incorrect inline function variable. Non-security fixes: - Various packaging fixes (boo#1210963, boo#1210938, boo#1211073) - Reduced install size (jsc#PED-1962).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for go1.19 fixes the following issues: Update to 1.19.9 (bnc#1200441): - CVE-2023-24539: fixed an improper sanitization of CSS values (bnc#1211029). - CVE-2023-24540: fixed an improper handling of JavaScript whitespace (bnc#1211030). - CVE-2023-29400: fixed an improper handling of empty HTML attributes (bnc#1211031). - runtime: automatically bump RLIMIT_NOFILE on Unix - cmd/compile: inlining function that references function literals generates bad code. - cmd/compile: encoding/binary.PutUint16 sometimes doesn't write. - crypto/tls: TLSv1.3 connection fails with invalid PSK binder. - cmd/compile: incorrect inline function variable. Non-security fixes: - Various packaging fixes (boo#1210963, boo#1210938, boo#1211073) - Reduced install size (jsc#PED-1962).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1200441
- https://bugzilla.suse.com/1210127
- https://bugzilla.suse.com/1210128
- https://bugzilla.suse.com/1210129
- https://bugzilla.suse.com/1210130
- https://bugzilla.suse.com/1210938
- https://bugzilla.suse.com/1210963
- https://bugzilla.suse.com/1211029
- https://bugzilla.suse.com/1211030
- https://bugzilla.suse.com/1211031
- https://bugzilla.suse.com/1211073
- https://www.suse.com/security/cve/CVE-2023-24534
- https://www.suse.com/security/cve/CVE-2023-24536
- https://www.suse.com/security/cve/CVE-2023-24537
- https://www.suse.com/security/cve/CVE-2023-24538
- https://www.suse.com/security/cve/CVE-2023-24539
- https://www.suse.com/security/cve/CVE-2023-24540
- https://www.suse.com/security/cve/CVE-2023-29400
- https://www.suse.com/support/update/announcement/2023/suse-su-20232127-1/