Skip to content

Update to go 1.18.6 to address CVE-2022-27664, CVE-2022-32190 - #3772

Merged
thaJeztah merged 1 commit into
docker:masterfrom
thaJeztah:bump_golang_1.18.6
Sep 8, 2022
Merged

Update to go 1.18.6 to address CVE-2022-27664, CVE-2022-32190#3772
thaJeztah merged 1 commit into
docker:masterfrom
thaJeztah:bump_golang_1.18.6

Conversation

@thaJeztah

Copy link
Copy Markdown
Member

From the mailing list:

We have just released Go versions 1.19.1 and 1.18.6, minor point releases.
These minor releases include 2 security fixes following the security policy:

  • net/http: handle server errors after sending GOAWAY
    A closing HTTP/2 server connection could hang forever waiting for a clean
    shutdown that was preempted by a subsequent fatal error. This failure mode
    could be exploited to cause a denial of service.

    Thanks to Bahruz Jabiyev, Tommaso Innocenti, Anthony Gavazzi, Steven Sprecher,
    and Kaan Onarlioglu for reporting this.

    This is CVE-2022-27664 and Go issue https://go.dev/issue/54658.

  • net/url: JoinPath does not strip relative path components in all circumstances
    JoinPath and URL.JoinPath would not remove ../ path components appended to a
    relative path. For example, JoinPath("https://go.dev", "../go") returned the
    URL https://go.dev/../go, despite the JoinPath documentation stating that
    ../ path elements are cleaned from the result.

    Thanks to q0jt for reporting this issue.

    This is CVE-2022-32190 and Go issue https://go.dev/issue/54385.

Release notes:

go1.18.6 (released 2022-09-06) includes security fixes to the net/http package,
as well as bug fixes to the compiler, the go command, the pprof command, the
runtime, and the crypto/tls, encoding/xml, and net packages. See the Go 1.18.6
milestone on the issue tracker for details;

https://github.com/golang/go/issues?q=milestone%3AGo1.18.6+label%3ACherryPickApproved

- Description for the changelog

- A picture of a cute animal (not mandatory but encouraged)

From the mailing list:
We have just released Go versions 1.19.1 and 1.18.6, minor point releases.
These minor releases include 2 security fixes following the security policy:
- net/http: handle server errors after sending GOAWAY
A closing HTTP/2 server connection could hang forever waiting for a clean
shutdown that was preempted by a subsequent fatal error. This failure mode
could be exploited to cause a denial of service.
Thanks to Bahruz Jabiyev, Tommaso Innocenti, Anthony Gavazzi, Steven Sprecher,
and Kaan Onarlioglu for reporting this.
This is CVE-2022-27664 and Go issue https://go.dev/issue/54658.
- net/url: JoinPath does not strip relative path components in all circumstances
JoinPath and URL.JoinPath would not remove `../` path components appended to a
relative path. For example, `JoinPath("https://go.dev", "../go")` returned the
URL `https://go.dev/../go`, despite the JoinPath documentation stating that
`../` path elements are cleaned from the result.
Thanks to q0jt for reporting this issue.
This is CVE-2022-32190 and Go issue https://go.dev/issue/54385.
Release notes:
go1.18.6 (released 2022-09-06) includes security fixes to the net/http package,
as well as bug fixes to the compiler, the go command, the pprof command, the
runtime, and the crypto/tls, encoding/xml, and net packages. See the Go 1.18.6
milestone on the issue tracker for details;
https://github.com/golang/go/issues?q=milestone%3AGo1.18.6+label%3ACherryPickApproved
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
@thaJeztah
thaJeztah merged commit a76f640 into docker:masterSep 8, 2022
@thaJeztah
thaJeztah deleted the bump_golang_1.18.6 branch September 8, 2022 08:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@thaJeztah@rumpl