FlawAtlas
Search the atlas
SUSE-SU-2023:3888-1 Not scored

Security update for Golang Prometheus

This update for Golang Prometheus fixes the following issues: golang-github-prometheus-alertmanager: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. golang-github-prometheus-node_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

Exploit probability Not scored
Published September 28, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 golang-github-prometheus-node_exporter
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Module for Basesystem 15 SP4 golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Module for Basesystem 15 SP5 golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Module for Package Hub 15 SP5 golang-github-prometheus-alertmanager
SUSE:Linux Enterprise Server 15 SP1-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server 15 SP2-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server 15 SP3-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 golang-github-prometheus-node_exporter
SUSE:Manager Client Tools 15 golang-github-prometheus-alertmanager
SUSE:Manager Client Tools for SLE Micro 5 golang-github-prometheus-node_exporter
SUSE:Manager Proxy 4.2 golang-github-prometheus-node_exporter
SUSE:Manager Proxy Module 4.2 golang-github-prometheus-alertmanager
SUSE:Manager Proxy Module 4.3 golang-github-prometheus-alertmanager
SUSE:Manager Server 4.2 golang-github-prometheus-node_exporter
openSUSE:Leap 15.4 golang-github-prometheus-alertmanager
openSUSE:Leap 15.4 golang-github-prometheus-node_exporter
openSUSE:Leap 15.5 golang-github-prometheus-alertmanager
openSUSE:Leap 15.5 golang-github-prometheus-node_exporter

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:3888-1

This update for Golang Prometheus fixes the following issues: golang-github-prometheus-alertmanager: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. golang-github-prometheus-node_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

View original source

05 / REFERENCES

Further evidence