跳转到帖子

Alma Linux: CVE-2022-41724: Moderate: go-toolset:rhel8 security and bug fix update (Multiple Advisories)

recommended_posts

发布于
  • Members

Alma Linux: CVE-2022-41724: Moderate: go-toolset:rhel8 security and bug fix update (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
02/28/2023
Created
05/23/2023
Added
05/23/2023
Modified
01/28/2025

Description

Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).

Solution(s)

  • alma-upgrade-aardvark-dns
  • alma-upgrade-buildah
  • alma-upgrade-buildah-tests
  • alma-upgrade-cockpit-podman
  • alma-upgrade-conmon
  • alma-upgrade-container-selinux
  • alma-upgrade-containernetworking-plugins
  • alma-upgrade-containers-common
  • alma-upgrade-crit
  • alma-upgrade-criu
  • alma-upgrade-criu-devel
  • alma-upgrade-criu-libs
  • alma-upgrade-crun
  • alma-upgrade-delve
  • alma-upgrade-fuse-overlayfs
  • alma-upgrade-go-toolset
  • alma-upgrade-golang
  • alma-upgrade-golang-bin
  • alma-upgrade-golang-docs
  • alma-upgrade-golang-misc
  • alma-upgrade-golang-race
  • alma-upgrade-golang-src
  • alma-upgrade-golang-tests
  • alma-upgrade-libslirp
  • alma-upgrade-libslirp-devel
  • alma-upgrade-netavark
  • alma-upgrade-oci-seccomp-bpf-hook
  • alma-upgrade-podman
  • alma-upgrade-podman-catatonit
  • alma-upgrade-podman-docker
  • alma-upgrade-podman-gvproxy
  • alma-upgrade-podman-plugins
  • alma-upgrade-podman-remote
  • alma-upgrade-podman-tests
  • alma-upgrade-python3-criu
  • alma-upgrade-python3-podman
  • alma-upgrade-runc
  • alma-upgrade-skopeo
  • alma-upgrade-skopeo-tests
  • alma-upgrade-slirp4netns
  • alma-upgrade-toolbox
  • alma-upgrade-toolbox-tests
  • alma-upgrade-udica

References

  • https://attackerkb.com/topics/cve-2022-41724
  • CVE - 2022-41724
  • https://errata.almalinux.org/8/ALSA-2023-3083.html
  • https://errata.almalinux.org/8/ALSA-2023-6938.html
  • https://errata.almalinux.org/8/ALSA-2023-6939.html
  • https://errata.almalinux.org/9/ALSA-2023-6363.html
  • https://errata.almalinux.org/9/ALSA-2023-6380.html
  • https://errata.almalinux.org/9/ALSA-2023-6402.html
  • https://errata.almalinux.org/9/ALSA-2023-6473.html
  • https://errata.almalinux.org/9/ALSA-2023-6474.html
View more
  • 查看数 698
  • 已创建
  • 最后回复