Bugzilla – Bug 1215985
VUL-0: CVE-2023-39323: go1.20,go1.21: cmd/go: line directives allows arbitrary execution during build
Last modified: 2024-05-16 12:47:18 UTC
"//line" directives can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compliation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploting this issue significantly more complex. This is CVE-2023-39323 and Go issue https://go.dev/issue/63211.
This is an autogenerated message for OBS integration: This bug (1215985) was mentioned in https://build.opensuse.org/request/show/1115933 Factory / go1.20 https://build.opensuse.org/request/show/1115934 Factory / go1.21
SUSE-SU-2023:4018-1: An update that solves one vulnerability and has one security fix can now be installed. Category: security (important) Bug References: 1206346, 1215985 CVE References: CVE-2023-39323 Sources used: openSUSE Leap 15.4 (src): go1.20-1.20.9-150000.1.26.1 openSUSE Leap 15.5 (src): go1.20-1.20.9-150000.1.26.1 Development Tools Module 15-SP4 (src): go1.20-1.20.9-150000.1.26.1 Development Tools Module 15-SP5 (src): go1.20-1.20.9-150000.1.26.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:4017-1: An update that solves one vulnerability and has one security fix can now be installed. Category: security (important) Bug References: 1212475, 1215985 CVE References: CVE-2023-39323 Sources used: openSUSE Leap 15.4 (src): go1.21-1.21.2-150000.1.9.1 openSUSE Leap 15.5 (src): go1.21-1.21.2-150000.1.9.1 Development Tools Module 15-SP4 (src): go1.21-1.21.2-150000.1.9.1 Development Tools Module 15-SP5 (src): go1.21-1.21.2-150000.1.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
This is an autogenerated message for OBS integration: This bug (1215985) was mentioned in https://build.opensuse.org/request/show/1121461 Backports:SLE-12 / go1.21
openSUSE-SU-2023:0360-1: An update that solves 8 vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1212475,1212667,1212669,1215084,1215085,1215086,1215087,1215090,1215985,1216109 CVE References: CVE-2023-39318,CVE-2023-39319,CVE-2023-39320,CVE-2023-39321,CVE-2023-39322,CVE-2023-39323,CVE-2023-39325,CVE-2023-44487 JIRA References: Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): go-1.21-41.1, go1.21-1.21.3-2.1
SUSE-SU-2023:4472-1: An update that solves five vulnerabilities can now be installed. Category: security (important) Bug References: 1206346, 1215985, 1216109, 1216943, 1216944 CVE References: CVE-2023-39323, CVE-2023-39325, CVE-2023-44487, CVE-2023-45283, CVE-2023-45284 Sources used: openSUSE Leap 15.4 (src): go1.20-openssl-1.20.11.1-150000.1.14.1 openSUSE Leap 15.5 (src): go1.20-openssl-1.20.11.1-150000.1.14.1 Development Tools Module 15-SP4 (src): go1.20-openssl-1.20.11.1-150000.1.14.1 Development Tools Module 15-SP5 (src): go1.20-openssl-1.20.11.1-150000.1.14.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:4469-1: An update that solves 10 vulnerabilities, contains one feature and has two security fixes can now be installed. Category: security (moderate) Bug References: 1212475, 1212667, 1212669, 1215084, 1215085, 1215086, 1215087, 1215090, 1215985, 1216109, 1216943, 1216944 CVE References: CVE-2023-39318, CVE-2023-39319, CVE-2023-39320, CVE-2023-39321, CVE-2023-39322, CVE-2023-39323, CVE-2023-39325, CVE-2023-44487, CVE-2023-45283, CVE-2023-45284 Jira References: SLE-18320 Sources used: openSUSE Leap 15.4 (src): go1.21-openssl-1.21.4.1-150000.1.5.1 openSUSE Leap 15.5 (src): go1.21-openssl-1.21.4.1-150000.1.5.1 Development Tools Module 15-SP4 (src): go1.21-openssl-1.21.4.1-150000.1.5.1 Development Tools Module 15-SP5 (src): go1.21-openssl-1.21.4.1-150000.1.5.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done