Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH v1 1/1] package/go: security bump to version go1.22.7
@ 2024-09-11 21:18 Christian Stewart via buildroot
  2024-09-14  9:00 ` Thomas Petazzoni via buildroot
  0 siblings, 1 reply; 6+ messages in thread
From: Christian Stewart via buildroot @ 2024-09-11 21:18 UTC (permalink / raw)
  To: buildroot; +Cc: Christian Stewart, Yann E . MORIN, Thomas Petazzoni

Fixes the following CVEs:

CVE-2024-34155: go/parser: stack exhaustion in all Parse* functions
CVE-2024-34156: encoding/gob: stack exhaustion in Decoder.Decode
CVE-2024-34158: go/build/constraint: stack exhaustion in Parse

https://go.dev/doc/devel/release#go1.22.7

Signed-off-by: Christian Stewart <christian@aperture.us>
---
 package/go/go-src/go-src.hash | 2 +-
 package/go/go.mk              | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/package/go/go-src/go-src.hash b/package/go/go-src/go-src.hash
index d300f6e2c9..f5727390f7 100644
--- a/package/go/go-src/go-src.hash
+++ b/package/go/go-src/go-src.hash
@@ -1,3 +1,3 @@
 # From https://go.dev/dl
-sha256  ac9c723f224969aee624bc34fd34c9e13f2a212d75c71c807de644bb46e112f6
 go1.22.5.src.tar.gz
+sha256  66432d87d85e0cfac3edffe637d5930fc4ddf5793313fe11e4a0f333023c879f
 go1.22.7.src.tar.gz
 sha256  2d36597f7117c38b006835ae7f537487207d8ec407aa9d9980794b2030cbc067
 LICENSE
diff --git a/package/go/go.mk b/package/go/go.mk
index 4c56660651..8b9651d7a1 100644
--- a/package/go/go.mk
+++ b/package/go/go.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################

-GO_VERSION = 1.22.5
+GO_VERSION = 1.22.7

 HOST_GO_GOPATH = $(HOST_DIR)/share/go-path
 HOST_GO_HOST_CACHE = $(HOST_DIR)/share/host-go-cache
-- 
2.39.2
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2024-09-19 19:56 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-09-11 21:18 [Buildroot] [PATCH v1 1/1] package/go: security bump to version go1.22.7 Christian Stewart via buildroot
2024-09-14  9:00 ` Thomas Petazzoni via buildroot
2024-09-15  3:07   ` Christian Stewart via buildroot
2024-09-15  7:31     ` Thomas Petazzoni via buildroot
2024-09-15 14:22       ` Christian Stewart via buildroot
2024-09-19 19:56   ` Peter Korsgaard

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox