Security update for go1.19
This update for go1.19 fixes the following issues: Update to go1.19.10 (bsc#1200441): - CVE-2023-29402: cmd/go: Fixed cgo code injection (bsc#1212073). - CVE-2023-29403: runtime: Fixed unexpected behavior of setuid/setgid binaries (bsc#1212074). - CVE-2023-29404: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212075). - CVE-2023-29405: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212076).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for go1.19 fixes the following issues: Update to go1.19.10 (bsc#1200441): - CVE-2023-29402: cmd/go: Fixed cgo code injection (bsc#1212073). - CVE-2023-29403: runtime: Fixed unexpected behavior of setuid/setgid binaries (bsc#1212074). - CVE-2023-29404: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212075). - CVE-2023-29405: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212076).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1200441
- https://bugzilla.suse.com/1212073
- https://bugzilla.suse.com/1212074
- https://bugzilla.suse.com/1212075
- https://bugzilla.suse.com/1212076
- https://www.suse.com/security/cve/CVE-2023-29402
- https://www.suse.com/security/cve/CVE-2023-29403
- https://www.suse.com/security/cve/CVE-2023-29404
- https://www.suse.com/security/cve/CVE-2023-29405
- https://www.suse.com/support/update/announcement/2023/suse-su-20232525-1/