SUSE-CU-2025:4220-1: Security update of bci/golang

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Jun 10 07:08:36 UTC 2025


SUSE Container Update Advisory: bci/golang
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2025:4220-1
Container Tags        : bci/golang:1.23 , bci/golang:1.23.10 , bci/golang:1.23.10-2.38.6 , bci/golang:oldstable , bci/golang:oldstable-2.38.6
Container Release     : 38.6
Severity              : important
Type                  : security
References            : 1229122 1244156 1244157 CVE-2025-0913 CVE-2025-4673 
-----------------------------------------------------------------

The container bci/golang was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:1848-1
Released:    Mon Jun  9 20:35:15 2025
Summary:     Security update for go1.23
Type:        security
Severity:    important
References:  1229122,1244156,1244157,CVE-2025-0913,CVE-2025-4673
This update for go1.23 fixes the following issues:

go1.23.10 (released 2025-06-05) includes security fixes to the
/http and os packages, as well as bug fixes to the linker.
(bsc#1229122 go1.23 release tracking CVE-2025-0913 CVE-2025-4673)

* CVE-2025-0913: os: inconsistent handling of O_CREATE|O_EXCL on Unix and Windows (bsc#1244157)
* CVE-2025-4673: net/http: sensitive headers not cleared on cross-origin redirect (bsc#1244156)

  * runtime/debug: BuildSetting does not document DefaultGODEBUG
  * cmd/link: Go 1.24.3 and 1.23.9 regression - duplicated definition of symbol dlopen


The following package changes have been done:

- go1.23-doc-1.23.10-150000.1.34.1 updated
- go1.23-1.23.10-150000.1.34.1 updated
- go1.23-race-1.23.10-150000.1.34.1 updated


More information about the sle-container-updates mailing list