Advisories ยป MGASA-2024-0376

Updated golang packages fix security vulnerabilities

Publication date: 27 Nov 2024
Modification date: 27 Nov 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-34155 , CVE-2024-34156 , CVE-2024-34158

Description

Calling any of the Parse functions on Go source code which contains
deeply nested literals can cause a panic due to stack exhaustion.
CVE-2024-34155
Calling Decoder.Decode on a message which contains deeply nested
structures can cause a panic due to stack exhaustion CVE-2024-34156
Calling Parse on a "// +build" build tag line with deeply nested
expressions can cause a panic due to stack exhaustion.CVE-2024-34158
                

References

SRPMS

9/core