SUSE-CU-2023:1963-1: Security update of bci/golang

sle-security-updates at sle-security-updates at
Sat Jun 17 07:06:37 UTC 2023

SUSE Container Update Advisory: bci/golang
Container Advisory ID : SUSE-CU-2023:1963-1
Container Tags        : bci/golang:1.20 , bci/golang:1.20-3.5 , bci/golang:latest
Container Release     : 3.5
Severity              : moderate
Type                  : security
References            : 1206346 1212073 1212074 1212075 1212076 CVE-2023-29402 CVE-2023-29403
                        CVE-2023-29404 CVE-2023-29405 

The container bci/golang was updated. The following patches have been included in this update:

Advisory ID: SUSE-SU-2023:2526-1
Released:    Fri Jun 16 17:33:35 2023
Summary:     Security update for go1.20
Type:        security
Severity:    moderate
References:  1206346,1212073,1212074,1212075,1212076,CVE-2023-29402,CVE-2023-29403,CVE-2023-29404,CVE-2023-29405
This update for go1.20 fixes the following issues:

Update to go1.20.5 (bsc#1206346):

- CVE-2023-29402: cmd/go: Fixed cgo code injection (bsc#1212073).                                                                                                                              
- CVE-2023-29403: runtime: Fixed unexpected behavior of setuid/setgid binaries (bsc#1212074).                                                                                                  
- CVE-2023-29404: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212075).                                                                                                                
- CVE-2023-29405: cmd/go: Fixed improper sanitization of LDFLAGS (bsc#1212076).                                                                                                                

The following package changes have been done:

- go1.20-1.20.5-150000.1.14.1 updated

More information about the sle-security-updates mailing list