FlawAtlas
Search the atlas
SUSE-SU-2025:01848-1 Not scored

Security update for go1.23

This update for go1.23 fixes the following issues: go1.23.10 (released 2025-06-05) includes security fixes to the /http and os packages, as well as bug fixes to the linker. (bsc#1229122 go1.23 release tracking CVE-2025-0913 CVE-2025-4673) * CVE-2025-0913: os: inconsistent handling of O_CREATE|O_EXCL on Unix and Windows (bsc#1244157) * CVE-2025-4673: net/http: sensitive headers not cleared on cross-origin redirect (bsc#1244156) * runtime/debug: BuildSetting does not document DefaultGODEBUG * cmd/link: Go 1.24.3 and 1.23.9 regression - duplicated definition of symbol dlopen

Exploit probability Not scored
Published June 9, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 go1.23
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS go1.23
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS go1.23
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS go1.23
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS go1.23
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS go1.23
SUSE:Linux Enterprise Module for Development Tools 15 SP6 go1.23
SUSE:Linux Enterprise Module for Development Tools 15 SP7 go1.23
SUSE:Linux Enterprise Server 15 SP3-LTSS go1.23
SUSE:Linux Enterprise Server 15 SP4-LTSS go1.23
SUSE:Linux Enterprise Server 15 SP5-LTSS go1.23
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 go1.23
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 go1.23
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 go1.23
openSUSE:Leap 15.6 go1.23

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:01848-1

This update for go1.23 fixes the following issues: go1.23.10 (released 2025-06-05) includes security fixes to the /http and os packages, as well as bug fixes to the linker. (bsc#1229122 go1.23 release tracking CVE-2025-0913 CVE-2025-4673) * CVE-2025-0913: os: inconsistent handling of O_CREATE|O_EXCL on Unix and Windows (bsc#1244157) * CVE-2025-4673: net/http: sensitive headers not cleared on cross-origin redirect (bsc#1244156) * runtime/debug: BuildSetting does not document DefaultGODEBUG * cmd/link: Go 1.24.3 and 1.23.9 regression - duplicated definition of symbol dlopen

View original source

05 / REFERENCES

Further evidence