Merge ~zhsj/ubuntu-cve-tracker:golang-20230411 into ubuntu-cve-tracker:master

Proposed by Shengjing Zhu
Status: Merged
Merged at revision: 7e34d0bb9246fea964782797d82755f7f15be865
Proposed branch: ~zhsj/ubuntu-cve-tracker:golang-20230411
Merge into: ubuntu-cve-tracker:master
Diff against target: 532 lines (+417/-12)
4 files modified
active/CVE-2023-24534 (+104/-3)
active/CVE-2023-24536 (+104/-3)
active/CVE-2023-24537 (+105/-3)
active/CVE-2023-24538 (+104/-3)
Reviewer Review Type Date Requested Status
Alex Murray Approve
Review via email: mp+440729@code.launchpad.net
To post a comment you must log in.
Revision history for this message
Shengjing Zhu (zhsj) wrote :

Hi, I'm triaging some CVE on the golang-1.x packages. It's the first time for me doing such. I just picked the latest 4. If it works for you, I'll continue with other untriaged CVE on golang-1.x packages.

Revision history for this message
Alex Murray (alexmurray) wrote :

Thanks for this - while reviewing this I noticed that the boilerplates/golang was missing golang-1.19 and golang-1.20 so I have updated it to list these new versions of golang in the newer Ubuntu releases.

review: Approve

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
1diff --git a/active/CVE-2023-24534 b/active/CVE-2023-24534
2index 3e3749f..7ceba7d 100644
3--- a/active/CVE-2023-24534
4+++ b/active/CVE-2023-24534
5@@ -25,17 +25,118 @@ Discovered-by:
6 Assigned-to:
7 CVSS:
8
9+Patches_golang-1.6:
10+upstream_golang-1.6: needs-triage
11+trusty_golang-1.6: ignored (out of standard support)
12+xenial_golang-1.6: ignored (out of standard support)
13+esm-infra/xenial_golang-1.6: needed
14+bionic_golang-1.6: DNE
15+focal_golang-1.6: DNE
16+jammy_golang-1.6: DNE
17+kinetic_golang-1.6: DNE
18+devel_golang-1.6: DNE
19+
20+Patches_golang-1.8:
21+upstream_golang-1.8: needs-triage
22+trusty_golang-1.8: ignored (out of standard support)
23+xenial_golang-1.8: ignored (out of standard support)
24+bionic_golang-1.8: needed
25+esm-apps/bionic_golang-1.8: needed
26+focal_golang-1.8: DNE
27+jammy_golang-1.8: DNE
28+kinetic_golang-1.8: DNE
29+devel_golang-1.8: DNE
30+
31+Patches_golang-1.9:
32+upstream_golang-1.9: needs-triage
33+trusty_golang-1.9: ignored (out of standard support)
34+xenial_golang-1.9: ignored (out of standard support)
35+bionic_golang-1.9: needed
36+esm-apps/bionic_golang-1.9: needed
37+focal_golang-1.9: DNE
38+jammy_golang-1.9: DNE
39+kinetic_golang-1.9: DNE
40+devel_golang-1.9: DNE
41+
42+Patches_golang-1.10:
43+upstream_golang-1.10: needs-triage
44+trusty_golang-1.10: ignored (out of standard support)
45+trusty/esm_golang-1.10: needed
46+xenial_golang-1.10: ignored (out of standard support)
47+esm-infra/xenial_golang-1.10: needed
48+bionic_golang-1.10: needed
49+focal_golang-1.10: DNE
50+jammy_golang-1.10: DNE
51+kinetic_golang-1.10: DNE
52+devel_golang-1.10: DNE
53+
54+Patches_golang-1.13:
55+upstream_golang-1.13: needs-triage
56+trusty_golang-1.13: ignored (out of standard support)
57+xenial_golang-1.13: ignored (out of standard support)
58+esm-apps/xenial_golang-1.13: needed
59+bionic_golang-1.13: needed
60+esm-apps/bionic_golang-1.13: needed
61+focal_golang-1.13: needed
62+jammy_golang-1.13: needed
63+esm-apps/jammy_golang-1.13: needed
64+kinetic_golang-1.13: needed
65+devel_golang-1.13: DNE
66+
67+Patches_golang-1.14:
68+upstream_golang-1.14: needs-triage
69+trusty_golang-1.14: ignored (out of standard support)
70+xenial_golang-1.14: ignored (out of standard support)
71+bionic_golang-1.14: DNE
72+focal_golang-1.14: needed
73+jammy_golang-1.14: DNE
74+kinetic_golang-1.14: DNE
75+devel_golang-1.14: DNE
76+
77+Patches_golang-1.16:
78+upstream_golang-1.16: needs-triage
79+trusty_golang-1.16: ignored (out of standard support)
80+xenial_golang-1.16: ignored (out of standard support)
81+bionic_golang-1.16: needed
82+focal_golang-1.16: needed
83+esm-apps/focal_golang-1.16: needed
84+jammy_golang-1.16: DNE
85+kinetic_golang-1.16: DNE
86+devel_golang-1.16: DNE
87+
88+Patches_golang-1.17:
89+upstream_golang-1.17: needs-triage
90+trusty_golang-1.17: ignored (out of standard support)
91+xenial_golang-1.17: ignored (out of standard support)
92+bionic_golang-1.17: DNE
93+focal_golang-1.17: DNE
94+jammy_golang-1.17: needed
95+kinetic_golang-1.17: DNE
96+devel_golang-1.17: DNE
97+
98+Patches_golang-1.18:
99+upstream_golang-1.18: needs-triage
100+trusty_golang-1.18: ignored (out of standard support)
101+xenial_golang-1.18: ignored (out of standard support)
102+bionic_golang-1.18: needed
103+focal_golang-1.18: needed
104+jammy_golang-1.18: needed
105+kinetic_golang-1.18: DNE
106+devel_golang-1.18: DNE
107+
108 Patches_golang-1.19:
109-upstream_golang-1.19: needs-triage
110+ upstream: https://github.com/golang/go/commit/d6759e7a059f4208f07aa781402841d7ddaaef96
111+upstream_golang-1.19: released (1.19.8-1)
112 trusty_golang-1.19: ignored (out of standard support)
113 xenial_golang-1.19: ignored (out of standard support)
114 bionic_golang-1.19: DNE
115 focal_golang-1.19: DNE
116 jammy_golang-1.19: DNE
117 kinetic_golang-1.19: needed
118-devel_golang-1.19: needs-triage
119+devel_golang-1.19: not-affected (1.19.8-1)
120
121 Patches_golang-1.20:
122+ upstream: https://github.com/golang/go/commit/3991f6c41c7dfd167e889234c0cf1d840475e93c
123 upstream_golang-1.20: released (1.20.3-1)
124 trusty_golang-1.20: ignored (out of standard support)
125 xenial_golang-1.20: ignored (out of standard support)
126@@ -43,4 +144,4 @@ bionic_golang-1.20: DNE
127 focal_golang-1.20: DNE
128 jammy_golang-1.20: DNE
129 kinetic_golang-1.20: DNE
130-devel_golang-1.20: needs-triage
131+devel_golang-1.20: not-affected (1.20.3-1)
132diff --git a/active/CVE-2023-24536 b/active/CVE-2023-24536
133index af352ae..1f29a9b 100644
134--- a/active/CVE-2023-24536
135+++ b/active/CVE-2023-24536
136@@ -40,17 +40,118 @@ Discovered-by:
137 Assigned-to:
138 CVSS:
139
140+Patches_golang-1.6:
141+upstream_golang-1.6: needs-triage
142+trusty_golang-1.6: ignored (out of standard support)
143+xenial_golang-1.6: ignored (out of standard support)
144+esm-infra/xenial_golang-1.6: needed
145+bionic_golang-1.6: DNE
146+focal_golang-1.6: DNE
147+jammy_golang-1.6: DNE
148+kinetic_golang-1.6: DNE
149+devel_golang-1.6: DNE
150+
151+Patches_golang-1.8:
152+upstream_golang-1.8: needs-triage
153+trusty_golang-1.8: ignored (out of standard support)
154+xenial_golang-1.8: ignored (out of standard support)
155+bionic_golang-1.8: needed
156+esm-apps/bionic_golang-1.8: needed
157+focal_golang-1.8: DNE
158+jammy_golang-1.8: DNE
159+kinetic_golang-1.8: DNE
160+devel_golang-1.8: DNE
161+
162+Patches_golang-1.9:
163+upstream_golang-1.9: needs-triage
164+trusty_golang-1.9: ignored (out of standard support)
165+xenial_golang-1.9: ignored (out of standard support)
166+bionic_golang-1.9: needed
167+esm-apps/bionic_golang-1.9: needed
168+focal_golang-1.9: DNE
169+jammy_golang-1.9: DNE
170+kinetic_golang-1.9: DNE
171+devel_golang-1.9: DNE
172+
173+Patches_golang-1.10:
174+upstream_golang-1.10: needs-triage
175+trusty_golang-1.10: ignored (out of standard support)
176+trusty/esm_golang-1.10: needed
177+xenial_golang-1.10: ignored (out of standard support)
178+esm-infra/xenial_golang-1.10: needed
179+bionic_golang-1.10: needed
180+focal_golang-1.10: DNE
181+jammy_golang-1.10: DNE
182+kinetic_golang-1.10: DNE
183+devel_golang-1.10: DNE
184+
185+Patches_golang-1.13:
186+upstream_golang-1.13: needs-triage
187+trusty_golang-1.13: ignored (out of standard support)
188+xenial_golang-1.13: ignored (out of standard support)
189+esm-apps/xenial_golang-1.13: needed
190+bionic_golang-1.13: needed
191+esm-apps/bionic_golang-1.13: needed
192+focal_golang-1.13: needed
193+jammy_golang-1.13: needed
194+esm-apps/jammy_golang-1.13: needed
195+kinetic_golang-1.13: needed
196+devel_golang-1.13: DNE
197+
198+Patches_golang-1.14:
199+upstream_golang-1.14: needed
200+trusty_golang-1.14: ignored (out of standard support)
201+xenial_golang-1.14: ignored (out of standard support)
202+bionic_golang-1.14: DNE
203+focal_golang-1.14: needed
204+jammy_golang-1.14: DNE
205+kinetic_golang-1.14: DNE
206+devel_golang-1.14: DNE
207+
208+Patches_golang-1.16:
209+upstream_golang-1.16: needs-triage
210+trusty_golang-1.16: ignored (out of standard support)
211+xenial_golang-1.16: ignored (out of standard support)
212+bionic_golang-1.16: needed
213+focal_golang-1.16: needed
214+esm-apps/focal_golang-1.16: needed
215+jammy_golang-1.16: DNE
216+kinetic_golang-1.16: DNE
217+devel_golang-1.16: DNE
218+
219+Patches_golang-1.17:
220+upstream_golang-1.17: needs-triage
221+trusty_golang-1.17: ignored (out of standard support)
222+xenial_golang-1.17: ignored (out of standard support)
223+bionic_golang-1.17: DNE
224+focal_golang-1.17: DNE
225+jammy_golang-1.17: needed
226+kinetic_golang-1.17: DNE
227+devel_golang-1.17: DNE
228+
229+Patches_golang-1.18:
230+upstream_golang-1.18: needs-triage
231+trusty_golang-1.18: ignored (out of standard support)
232+xenial_golang-1.18: ignored (out of standard support)
233+bionic_golang-1.18: needed
234+focal_golang-1.18: needed
235+jammy_golang-1.18: needed
236+kinetic_golang-1.18: DNE
237+devel_golang-1.18: DNE
238+
239 Patches_golang-1.19:
240-upstream_golang-1.19: needs-triage
241+ upstream: https://github.com/golang/go/commit/7917b5f31204528ea72e0629f0b7d52b35b27538
242+upstream_golang-1.19: released (1.19.8-1)
243 trusty_golang-1.19: ignored (out of standard support)
244 xenial_golang-1.19: ignored (out of standard support)
245 bionic_golang-1.19: DNE
246 focal_golang-1.19: DNE
247 jammy_golang-1.19: DNE
248 kinetic_golang-1.19: needed
249-devel_golang-1.19: needs-triage
250+devel_golang-1.19: not-affected (1.19.8-1)
251
252 Patches_golang-1.20:
253+ upstream: https://github.com/golang/go/commit/bf8c7c575c8a552d9d79deb29e80854dc88528d0
254 upstream_golang-1.20: released (1.20.3-1)
255 trusty_golang-1.20: ignored (out of standard support)
256 xenial_golang-1.20: ignored (out of standard support)
257@@ -58,4 +159,4 @@ bionic_golang-1.20: DNE
258 focal_golang-1.20: DNE
259 jammy_golang-1.20: DNE
260 kinetic_golang-1.20: DNE
261-devel_golang-1.20: needs-triage
262+devel_golang-1.20: not-affected (1.20.3-1)
263diff --git a/active/CVE-2023-24537 b/active/CVE-2023-24537
264index 3df7358..7d11d38 100644
265--- a/active/CVE-2023-24537
266+++ b/active/CVE-2023-24537
267@@ -12,6 +12,8 @@ Description:
268 integer overflow.
269 Ubuntu-Description:
270 Notes:
271+ zhsj> Introduced by:
272+ zhsj> https://github.com/golang/go/commit/99c30211b1e0b3ac4e5d32f3ae5eaf759c23195f
273 Mitigation:
274 Bugs:
275 Priority: medium
276@@ -19,17 +21,117 @@ Discovered-by:
277 Assigned-to:
278 CVSS:
279
280+Patches_golang-1.6:
281+upstream_golang-1.6: needs-triage
282+trusty_golang-1.6: ignored (out of standard support)
283+xenial_golang-1.6: ignored (out of standard support)
284+esm-infra/xenial_golang-1.6: not-affected (code not present)
285+bionic_golang-1.6: DNE
286+focal_golang-1.6: DNE
287+jammy_golang-1.6: DNE
288+kinetic_golang-1.6: DNE
289+devel_golang-1.6: DNE
290+
291+Patches_golang-1.8:
292+upstream_golang-1.8: needs-triage
293+trusty_golang-1.8: ignored (out of standard support)
294+xenial_golang-1.8: ignored (out of standard support)
295+bionic_golang-1.8: not-affected (code not present)
296+esm-apps/bionic_golang-1.8: not-affected (code not present)
297+focal_golang-1.8: DNE
298+jammy_golang-1.8: DNE
299+kinetic_golang-1.8: DNE
300+devel_golang-1.8: DNE
301+
302+Patches_golang-1.9:
303+upstream_golang-1.9: needs-triage
304+trusty_golang-1.9: ignored (out of standard support)
305+xenial_golang-1.9: ignored (out of standard support)
306+bionic_golang-1.9: not-affected (code not present)
307+esm-apps/bionic_golang-1.9: not-affected (code not present)
308+focal_golang-1.9: DNE
309+jammy_golang-1.9: DNE
310+kinetic_golang-1.9: DNE
311+devel_golang-1.9: DNE
312+Patches_golang-1.10:
313+upstream_golang-1.10: not-affected (code not present)
314+trusty_golang-1.10: ignored (out of standard support)
315+trusty/esm_golang-1.10: not-affected (code not present)
316+xenial_golang-1.10: ignored (out of standard support)
317+esm-infra/xenial_golang-1.10: not-affected (code not present)
318+bionic_golang-1.10: not-affected (code not present)
319+focal_golang-1.10: DNE
320+jammy_golang-1.10: DNE
321+kinetic_golang-1.10: DNE
322+devel_golang-1.10: DNE
323+
324+Patches_golang-1.13:
325+upstream_golang-1.13: needs-triage
326+trusty_golang-1.13: ignored (out of standard support)
327+xenial_golang-1.13: ignored (out of standard support)
328+esm-apps/xenial_golang-1.13: needed
329+bionic_golang-1.13: needed
330+esm-apps/bionic_golang-1.13: needed
331+focal_golang-1.13: needed
332+jammy_golang-1.13: needed
333+esm-apps/jammy_golang-1.13: needed
334+kinetic_golang-1.13: needed
335+devel_golang-1.13: DNE
336+
337+Patches_golang-1.14:
338+upstream_golang-1.14: needs-triage
339+trusty_golang-1.14: ignored (out of standard support)
340+xenial_golang-1.14: ignored (out of standard support)
341+bionic_golang-1.14: DNE
342+focal_golang-1.14: needed
343+jammy_golang-1.14: DNE
344+kinetic_golang-1.14: DNE
345+devel_golang-1.14: DNE
346+
347+Patches_golang-1.16:
348+upstream_golang-1.16: needs-triage
349+trusty_golang-1.16: ignored (out of standard support)
350+xenial_golang-1.16: ignored (out of standard support)
351+bionic_golang-1.16: needed
352+focal_golang-1.16: needed
353+esm-apps/focal_golang-1.16: needed
354+jammy_golang-1.16: DNE
355+kinetic_golang-1.16: DNE
356+devel_golang-1.16: DNE
357+
358+Patches_golang-1.17:
359+upstream_golang-1.17: needs-triage
360+trusty_golang-1.17: ignored (out of standard support)
361+xenial_golang-1.17: ignored (out of standard support)
362+bionic_golang-1.17: DNE
363+focal_golang-1.17: DNE
364+jammy_golang-1.17: needed
365+kinetic_golang-1.17: DNE
366+devel_golang-1.17: DNE
367+
368+Patches_golang-1.18:
369+upstream_golang-1.18: needs-triage
370+trusty_golang-1.18: ignored (out of standard support)
371+xenial_golang-1.18: ignored (out of standard support)
372+bionic_golang-1.18: needed
373+focal_golang-1.18: needed
374+jammy_golang-1.18: needed
375+kinetic_golang-1.18: DNE
376+devel_golang-1.18: DNE
377+
378 Patches_golang-1.19:
379-upstream_golang-1.19: needs-triage
380+ upstream: https://github.com/golang/go/commit/126a1d02da82f93ede7ce0bd8d3c51ef627f2104
381+upstream_golang-1.19: released (1.19.8-1)
382 trusty_golang-1.19: ignored (out of standard support)
383 xenial_golang-1.19: ignored (out of standard support)
384 bionic_golang-1.19: DNE
385 focal_golang-1.19: DNE
386 jammy_golang-1.19: DNE
387 kinetic_golang-1.19: needed
388-devel_golang-1.19: needs-triage
389+devel_golang-1.19: not-affected (1.19.8-1)
390
391 Patches_golang-1.20:
392+ upstream: https://github.com/golang/go/commit/e7c4b07ecf6b367f1afc9cc48cde963829dd0aab
393 upstream_golang-1.20: released (1.20.3-1)
394 trusty_golang-1.20: ignored (out of standard support)
395 xenial_golang-1.20: ignored (out of standard support)
396@@ -37,4 +139,4 @@ bionic_golang-1.20: DNE
397 focal_golang-1.20: DNE
398 jammy_golang-1.20: DNE
399 kinetic_golang-1.20: DNE
400-devel_golang-1.20: needs-triage
401+devel_golang-1.20: not-affected (1.20.3-1)
402diff --git a/active/CVE-2023-24538 b/active/CVE-2023-24538
403index c43d9e3..4a531a4 100644
404--- a/active/CVE-2023-24538
405+++ b/active/CVE-2023-24538
406@@ -31,17 +31,118 @@ Discovered-by:
407 Assigned-to:
408 CVSS:
409
410+Patches_golang-1.6:
411+upstream_golang-1.6: needs-triage
412+trusty_golang-1.6: ignored (out of standard support)
413+xenial_golang-1.6: ignored (out of standard support)
414+esm-infra/xenial_golang-1.6: needed
415+bionic_golang-1.6: DNE
416+focal_golang-1.6: DNE
417+jammy_golang-1.6: DNE
418+kinetic_golang-1.6: DNE
419+devel_golang-1.6: DNE
420+
421+Patches_golang-1.8:
422+upstream_golang-1.8: needs-triage
423+trusty_golang-1.8: ignored (out of standard support)
424+xenial_golang-1.8: ignored (out of standard support)
425+bionic_golang-1.8: needed
426+esm-apps/bionic_golang-1.8: needed
427+focal_golang-1.8: DNE
428+jammy_golang-1.8: DNE
429+kinetic_golang-1.8: DNE
430+devel_golang-1.8: DNE
431+
432+Patches_golang-1.9:
433+upstream_golang-1.9: needs-triage
434+trusty_golang-1.9: ignored (out of standard support)
435+xenial_golang-1.9: ignored (out of standard support)
436+bionic_golang-1.9: needed
437+esm-apps/bionic_golang-1.9: needed
438+focal_golang-1.9: DNE
439+jammy_golang-1.9: DNE
440+kinetic_golang-1.9: DNE
441+devel_golang-1.9: DNE
442+
443+Patches_golang-1.10:
444+upstream_golang-1.10: needs-triage
445+trusty_golang-1.10: ignored (out of standard support)
446+trusty/esm_golang-1.10: needed
447+xenial_golang-1.10: ignored (out of standard support)
448+esm-infra/xenial_golang-1.10: needed
449+bionic_golang-1.10: needed
450+focal_golang-1.10: DNE
451+jammy_golang-1.10: DNE
452+kinetic_golang-1.10: DNE
453+devel_golang-1.10: DNE
454+
455+Patches_golang-1.13:
456+upstream_golang-1.13: needs-triage
457+trusty_golang-1.13: ignored (out of standard support)
458+xenial_golang-1.13: ignored (out of standard support)
459+esm-apps/xenial_golang-1.13: needed
460+bionic_golang-1.13: needed
461+esm-apps/bionic_golang-1.13: needed
462+focal_golang-1.13: needed
463+jammy_golang-1.13: needed
464+esm-apps/jammy_golang-1.13: needed
465+kinetic_golang-1.13: needed
466+devel_golang-1.13: DNE
467+
468+Patches_golang-1.14:
469+upstream_golang-1.14: needs-triage
470+trusty_golang-1.14: ignored (out of standard support)
471+xenial_golang-1.14: ignored (out of standard support)
472+bionic_golang-1.14: DNE
473+focal_golang-1.14: needed
474+jammy_golang-1.14: DNE
475+kinetic_golang-1.14: DNE
476+devel_golang-1.14: DNE
477+
478+Patches_golang-1.16:
479+upstream_golang-1.16: needs-triage
480+trusty_golang-1.16: ignored (out of standard support)
481+xenial_golang-1.16: ignored (out of standard support)
482+bionic_golang-1.16: needed
483+focal_golang-1.16: needed
484+esm-apps/focal_golang-1.16: needed
485+jammy_golang-1.16: DNE
486+kinetic_golang-1.16: DNE
487+devel_golang-1.16: DNE
488+
489+Patches_golang-1.17:
490+upstream_golang-1.17: needs-triage
491+trusty_golang-1.17: ignored (out of standard support)
492+xenial_golang-1.17: ignored (out of standard support)
493+bionic_golang-1.17: DNE
494+focal_golang-1.17: DNE
495+jammy_golang-1.17: needed
496+kinetic_golang-1.17: DNE
497+devel_golang-1.17: DNE
498+
499+Patches_golang-1.18:
500+upstream_golang-1.18: needs-triage
501+trusty_golang-1.18: ignored (out of standard support)
502+xenial_golang-1.18: ignored (out of standard support)
503+bionic_golang-1.18: needed
504+focal_golang-1.18: needed
505+jammy_golang-1.18: needed
506+kinetic_golang-1.18: DNE
507+devel_golang-1.18: DNE
508+
509 Patches_golang-1.19:
510-upstream_golang-1.19: needs-triage
511+ upstream: https://github.com/golang/go/commit/b1e3ecfa06b67014429a197ec5e134ce4303ad9b
512+upstream_golang-1.19: released (1.19.8-1)
513 trusty_golang-1.19: ignored (out of standard support)
514 xenial_golang-1.19: ignored (out of standard support)
515 bionic_golang-1.19: DNE
516 focal_golang-1.19: DNE
517 jammy_golang-1.19: DNE
518 kinetic_golang-1.19: needed
519-devel_golang-1.19: needs-triage
520+devel_golang-1.19: not-affected (1.19.8-1)
521
522 Patches_golang-1.20:
523+ upstream: https://github.com/golang/go/commit/20374d1d759bc4e17486bde1cb9dca5be37d9e52
524 upstream_golang-1.20: released (1.20.3-1)
525 trusty_golang-1.20: ignored (out of standard support)
526 xenial_golang-1.20: ignored (out of standard support)
527@@ -49,4 +150,4 @@ bionic_golang-1.20: DNE
528 focal_golang-1.20: DNE
529 jammy_golang-1.20: DNE
530 kinetic_golang-1.20: DNE
531-devel_golang-1.20: needs-triage
532+devel_golang-1.20: not-affected (1.20.3-1)

Subscribers

People subscribed via source and target branches