UbuntuUpdates.org

Package "golang-1.22"

Name: golang-1.22

Description:

Go programming language compiler - metapackage

Latest version: 1.22.2-2~22.04.1
Release: jammy (22.04)
Level: security
Repository: universe
Homepage: https://go.dev/

Links


Download "golang-1.22"


Other versions of "golang-1.22" in Jammy

Repository Area Version
updates universe 1.22.2-2~22.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.22.2-2~22.04.1 2024-07-09 15:07:12 UTC

  golang-1.22 (1.22.2-2~22.04.1) jammy-security; urgency=medium

  * SECURITY UPDATE: denial of service issue
    - debian/patches/CVE-2024-24788.patch: net: check SkipAdditional error
      result
    - CVE-2024-24788
  * SECURITY UPDATE: denial of service issue
    - debian/patches/CVE-2024-24789.patch: archive/zip: treat truncated
      EOCDR comment as an error
    - debian/source/include-binaries: Add zip testdata file
    - CVE-2024-24789
  * SECURITY UPDATE: incorrect IPv4-mapped IPv6 addresses issue
    - debian/patches/CVE-2024-24790.patch: net/netip: check if address is
      v6 mapped in Is methods
    - CVE-2024-24790

 -- Nishit Majithia <email address hidden> Mon, 08 Jul 2024 17:45:50 +0530

CVE-2024-24788 A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.
CVE-2024-24789 The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment cou
CVE-2024-24790 The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which woul



About   -   Send Feedback to @ubuntu_updates