🛡️ SUSE-SU-2024:3938-1 — go1.22-openssl (CVE-2024-34155 +13 more)
Description
Security update for go1.22-openssl
This update for go1.22-openssl fixes the following issues:
This update ships go1.22-openssl 1.22.7.1 (jsc#SLE-18320)
- Update to version 1.22.7.1 cut from the go1.22-fips-release
branch at the revision tagged go1.22.7-1-openssl-fips.
- Update to Go 1.22.7 (#229)
- go1.22.7 (released 2024-09-05) includes security fixes to the
encoding/gob, go/build/constraint, and go/parser packages, as
well as bug fixes to the fix command and the runtime.
CVE-2024-34155 CVE-2024-34156 CVE-2024-34158:
- go#69142 go#69138 bsc#1230252 security: fix CVE-2024-34155 go/parser: stack exhaustion in all Parse* functions (CVE-2024-34155)
- go#69144 go#69139 bsc#1230253 security: fix CVE-2024-34156 encoding/gob: stack exhaustion in Decoder.Decode (CVE-2024-34156)
- go#69148 go#69141 bsc#1230254 security: fix CVE-2024-34158 go/build/constraint: stack exhaustion in Parse (CVE-2024-34158)
- go#68811 os: TestChtimes failures
- go#68825 cmd/fix: fails to run on modules whose go directive value is in '1.n.m' format introduced in Go 1.21.0
- go#68972 cmd/cgo: aix c-archive corrupting stack
- go1.22.6 (released 2024-08-06) includes fixes to the go command,
the compiler, the linker, the trace command, the covdata command,
and the bytes, go/types, and os/exec packages.
- go#68594 cmd/compile: internal compiler error with zero-size types
- go#68546 cmd/trace/v2: pprof profiles always empty
- go#68492 cmd/covdata: too many open files due to defer f.Close() in for loop
- go#68475 bytes: IndexByte can return -4294967295 when memory usage is above 2^31 on js/wasm
- go#68370 go/types: assertion failure in recent range statement checking logic
- go#68331 os/exec: modifications to Path ignored when *Cmd is created using Command with an absolute path on Windows
- go#68230 cmd/compile: inconsistent integer arithmetic result on Go 1.22+arm64 with/without -race
- go#68222 cmd/go: list with -export and -covermode=atomic fails to build
- go#68198 cmd/link: issues with Xcode 16 beta
- Update to version 1.22.5.3 cut from the go1.22-fips-release
branch at the revision tagged go1.22.5-3-openssl-fips.
- Only load openssl if fips == '1'
Avoid loading openssl whenever GOLANG_FIPS is not 1.
Previously only an unset variable would cause the library load
to be skipped, but users may also expect to be able to set eg.
GOLANG_FIPS=0 in environments without openssl.
- Update to version 1.22.5.2 cut from the go1.22-fips-release
branch at the revision tagged go1.22.5-2-openssl-fips.
- Only load OpenSSL when in FIPS mode
- Update to version 1.22.5.1 cut from the go1.22-fips-release
branch at the revision tagged go1.22.5-1-openssl-fips.
- Update to go1.22.5
- go1.22.5 (released 2024-07-02) includes security fixes to the
net/http package, as well as bug fixes to the compiler, cgo, the
go command, the linker, the runtime, and the crypto/tls,
go/types, net, net/http, and os/exec packages.
CVE-2024-24791:
- go#68200 go#67555 bsc#1227314 security: fix CVE CVE-2024-24791 net/http: expect: 100-continue handling is broken in various ways
- go#65983 cmd/compile: hash of unhashable type
- go#65994 crypto/tls: segfault when calling tlsrsakex.IncNonDefault()
- go#66598 os/exec: calling Cmd.Start after setting Cmd.Path manually to absolute path without '.exe' no longer implicitly adds '.exe' in Go 1.22
- go#67298 runtime: 'fatal: morestack on g0' on amd64 after upgrade to Go 1.21, stale bounds
- go#67715 cmd/cgo/internal/swig,cmd/go,x/build: swig cgo tests incompatible with C++ toolchain on builders
- go#67798 cmd/compile: internal compiler error: unexpected type: <nil> (<nil>) in for-range
- go#67820 cmd/compile: package-level variable initialization with constant dependencies doesn't match order specified in Go spec
- go#67850 go/internal/gccgoimporter: go building failing with gcc 14.1.0
- go#67934 net: go DNS resolver fails to connect to local DNS server
- go#67945 cmd/link: using -fuzz with test that links with cgo on darwin causes linker failure
- go#68052 cmd/go: go list -u -m all fails loading module retractions: module requires go >= 1.N+1 (running go 1.N)
- go#68122 cmd/link: runtime.mach_vm_region_trampoline: unsupported dynamic relocation for symbol libc_mach_task_self_ (type=29 (R_GOTPCREL) stype=46 (SDYNIMPORT))
- Update to version 1.22.4.1 cut from the go1.22-fips-release
branch at the revision tagged go1.22.4-1-openssl-fips.
- Update to go1.22.4
- go1.22.4 (released 2024-06-04) includes security fixes to the
archive/zip and net/netip packages, as well as bug fixes to the
compiler, the go command, the linker, the runtime, and the os
package.
CVE-2024-24789 CVE-2024-24790:
- go#67554 go#66869 bsc#1225973 security: fix CVE-2024-24789 archive/zip: EOCDR comment length handling is inconsistent with other ZIP implementations
- go#67682 go#67680 bsc#1225974 security: fix CVE-2024-24790 net/netip: unexpecte
Affected software
SUSE-SU-2024:3938-1 is recorded against 1 package.
- go1.22-openssl (fixed in 1.22.7.1-150600.13.3.1)
Timeline and source
Published on 7 November 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| go1.22-openssl | — | 1.22.7.1-150600.13.3.1 |
References
Similar Threats
- Unknown openSUSE-SU-2026:21447-1
- Unknown SUSE-SU-2025:1555-1
- Unknown SUSE-SU-2024:3772-1
Free Vulnerability Check
Is your site affected by SUSE-SU-2024:3938-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:3938-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.