[Apollo] Advisories Red Hat Advisories Statistics light light Login

RHSA-2024:4212

Security
Issued at: 2024-07-02
launch
Open original
Override

Synopsis

Moderate: golang security update



Description

The golang packages provide the Go programming language compiler.

Security Fix(es):

* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)

* golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Red Hat Enterprise Linux for ARM 64 - 9 Red Hat Enterprise Linux for IBM z Systems - 9 Red Hat Enterprise Linux for Power, little endian - 9 Red Hat Enterprise Linux for x86_64 - 9

Fixes

2292668 2292787

CVEs

CVE-2024-24789 CVE-2024-24790

Affected packages

golang-0:1.21.11-1.el9_4.aarch64 golang-0:1.21.11-1.el9_4.ppc64le golang-0:1.21.11-1.el9_4.s390x golang-0:1.21.11-1.el9_4.src golang-0:1.21.11-1.el9_4.x86_64 golang-bin-0:1.21.11-1.el9_4.aarch64 golang-bin-0:1.21.11-1.el9_4.ppc64le golang-bin-0:1.21.11-1.el9_4.s390x golang-bin-0:1.21.11-1.el9_4.x86_64 golang-docs-0:1.21.11-1.el9_4.noarch golang-misc-0:1.21.11-1.el9_4.noarch golang-src-0:1.21.11-1.el9_4.noarch golang-tests-0:1.21.11-1.el9_4.noarch go-toolset-0:1.21.11-1.el9_4.aarch64 go-toolset-0:1.21.11-1.el9_4.ppc64le go-toolset-0:1.21.11-1.el9_4.s390x go-toolset-0:1.21.11-1.el9_4.x86_64