-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2022-0e313cc582 2022-10-14 12:57:09.362168 --------------------------------------------------------------------------------
Name : golang Product : Fedora 36 Version : 1.18.7 Release : 1.fc36 URL : https://go.dev Summary : The Go Programming Language Description : The Go Programming Language.
-------------------------------------------------------------------------------- Update Information:
This release includes security fixes to the archive/tar, net/http/httputil, and regexp packages, as well as bug fixes to the compiler, the linker, and the go/types package. See the [Go 1.18.7 milestone](https://github.com/golang/go/iss ues?q=milestone%3AGo1.18.7+label%3ACherryPickApproved) on the issue tracker for details. -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 4 2022 Alejandro S��ez asm@redhat.com - 1.18.7-1 - Update to 1.18.7 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2132875 - CVE-2022-41715 golang: regexp/syntax: limit memory used by parsing regexps [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2132875 [ 2 ] Bug #2132879 - CVE-2022-2879 golang: archive/tar: unbounded memory consumption when reading headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2132879 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-0e313cc582' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
package-announce@lists.fedoraproject.org