🛡️ SUSE-SU-2024:3938-1 — go1.22-openssl (CVE-2024-34155 +13 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for go1.22-openssl

This update for go1.22-openssl fixes the following issues:

This update ships go1.22-openssl 1.22.7.1 (jsc#SLE-18320)

  • Update to version 1.22.7.1 cut from the go1.22-fips-release

branch at the revision tagged go1.22.7-1-openssl-fips.

  • Update to Go 1.22.7 (#229)
  • go1.22.7 (released 2024-09-05) includes security fixes to the

encoding/gob, go/build/constraint, and go/parser packages, as

well as bug fixes to the fix command and the runtime.

CVE-2024-34155 CVE-2024-34156 CVE-2024-34158:

  • go#69142 go#69138 bsc#1230252 security: fix CVE-2024-34155 go/parser: stack exhaustion in all Parse* functions (CVE-2024-34155)
  • go#69144 go#69139 bsc#1230253 security: fix CVE-2024-34156 encoding/gob: stack exhaustion in Decoder.Decode (CVE-2024-34156)
  • go#69148 go#69141 bsc#1230254 security: fix CVE-2024-34158 go/build/constraint: stack exhaustion in Parse (CVE-2024-34158)
  • go#68811 os: TestChtimes failures
  • go#68825 cmd/fix: fails to run on modules whose go directive value is in '1.n.m' format introduced in Go 1.21.0
  • go#68972 cmd/cgo: aix c-archive corrupting stack
  • go1.22.6 (released 2024-08-06) includes fixes to the go command,

the compiler, the linker, the trace command, the covdata command,

and the bytes, go/types, and os/exec packages.

  • go#68594 cmd/compile: internal compiler error with zero-size types
  • go#68546 cmd/trace/v2: pprof profiles always empty
  • go#68492 cmd/covdata: too many open files due to defer f.Close() in for loop
  • go#68475 bytes: IndexByte can return -4294967295 when memory usage is above 2^31 on js/wasm
  • go#68370 go/types: assertion failure in recent range statement checking logic
  • go#68331 os/exec: modifications to Path ignored when *Cmd is created using Command with an absolute path on Windows
  • go#68230 cmd/compile: inconsistent integer arithmetic result on Go 1.22+arm64 with/without -race
  • go#68222 cmd/go: list with -export and -covermode=atomic fails to build
  • go#68198 cmd/link: issues with Xcode 16 beta
  • Update to version 1.22.5.3 cut from the go1.22-fips-release

branch at the revision tagged go1.22.5-3-openssl-fips.

  • Only load openssl if fips == '1'

Avoid loading openssl whenever GOLANG_FIPS is not 1.

Previously only an unset variable would cause the library load

to be skipped, but users may also expect to be able to set eg.

GOLANG_FIPS=0 in environments without openssl.

  • Update to version 1.22.5.2 cut from the go1.22-fips-release

branch at the revision tagged go1.22.5-2-openssl-fips.

  • Only load OpenSSL when in FIPS mode
  • Update to version 1.22.5.1 cut from the go1.22-fips-release

branch at the revision tagged go1.22.5-1-openssl-fips.

  • Update to go1.22.5
  • go1.22.5 (released 2024-07-02) includes security fixes to the

net/http package, as well as bug fixes to the compiler, cgo, the

go command, the linker, the runtime, and the crypto/tls,

go/types, net, net/http, and os/exec packages.

CVE-2024-24791:

  • go#68200 go#67555 bsc#1227314 security: fix CVE CVE-2024-24791 net/http: expect: 100-continue handling is broken in various ways
  • go#65983 cmd/compile: hash of unhashable type
  • go#65994 crypto/tls: segfault when calling tlsrsakex.IncNonDefault()
  • go#66598 os/exec: calling Cmd.Start after setting Cmd.Path manually to absolute path without '.exe' no longer implicitly adds '.exe' in Go 1.22
  • go#67298 runtime: 'fatal: morestack on g0' on amd64 after upgrade to Go 1.21, stale bounds
  • go#67715 cmd/cgo/internal/swig,cmd/go,x/build: swig cgo tests incompatible with C++ toolchain on builders
  • go#67798 cmd/compile: internal compiler error: unexpected type: <nil> (<nil>) in for-range
  • go#67820 cmd/compile: package-level variable initialization with constant dependencies doesn't match order specified in Go spec
  • go#67850 go/internal/gccgoimporter: go building failing with gcc 14.1.0
  • go#67934 net: go DNS resolver fails to connect to local DNS server
  • go#67945 cmd/link: using -fuzz with test that links with cgo on darwin causes linker failure
  • go#68052 cmd/go: go list -u -m all fails loading module retractions: module requires go >= 1.N+1 (running go 1.N)
  • go#68122 cmd/link: runtime.mach_vm_region_trampoline: unsupported dynamic relocation for symbol libc_mach_task_self_ (type=29 (R_GOTPCREL) stype=46 (SDYNIMPORT))
  • Update to version 1.22.4.1 cut from the go1.22-fips-release

branch at the revision tagged go1.22.4-1-openssl-fips.

  • Update to go1.22.4
  • go1.22.4 (released 2024-06-04) includes security fixes to the

archive/zip and net/netip packages, as well as bug fixes to the

compiler, the go command, the linker, the runtime, and the os

package.

CVE-2024-24789 CVE-2024-24790:

  • go#67554 go#66869 bsc#1225973 security: fix CVE-2024-24789 archive/zip: EOCDR comment length handling is inconsistent with other ZIP implementations
  • go#67682 go#67680 bsc#1225974 security: fix CVE-2024-24790 net/netip: unexpecte

Affected software

SUSE-SU-2024:3938-1 is recorded against 1 package.

  • go1.22-openssl (fixed in 1.22.7.1-150600.13.3.1)

Timeline and source

Published on 7 November 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-11-07
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
go1.22-openssl 1.22.7.1-150600.13.3.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:3938-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:3938-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2024