Bugzilla – Bug 1191468
VUL-0: CVE-2021-38297: go1.15,go1.16,go1.17: misc/wasm, cmd/link: do not let command line args overwrite global data
Last modified: 2023-03-02 16:30:21 UTC
When invoking functions from WASM modules, built using GOARCH=wasm GOOS=js, passing very large arguments can cause portions of the module to be overwritten with data from the arguments. If using wasm_exec.js to execute WASM modules, users will need to replace their copy (as described in https://golang.org/wiki/WebAssembly#getting-started) after rebuilding any modules. This is issue go#48797 and CVE-2021-38297. Thanks to Ben Lubar for reporting this issue. Refs: https://github.com/golang/go/issues/48797
This is an autogenerated message for OBS integration: This bug (1191468) was mentioned in https://build.opensuse.org/request/show/924125 Factory / go1.16 https://build.opensuse.org/request/show/924126 Factory / go1.17
SUSE-SU-2021:3487-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1182345,1191468 CVE References: CVE-2021-38297 JIRA References: Sources used: SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): go1.16-1.16.9-1.29.1 SUSE Linux Enterprise Module for Development Tools 15-SP2 (src): go1.16-1.16.9-1.29.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:3487-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1182345,1191468 CVE References: CVE-2021-38297 JIRA References: Sources used: openSUSE Leap 15.3 (src): go1.16-1.16.9-1.29.1
openSUSE-SU-2021:3488-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1190649,1191468 CVE References: CVE-2021-38297 JIRA References: Sources used: openSUSE Leap 15.3 (src): go1.17-1.17.2-1.6.2
SUSE-SU-2021:3488-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1190649,1191468 CVE References: CVE-2021-38297 JIRA References: Sources used: SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): go1.17-1.17.2-1.6.2 SUSE Linux Enterprise Module for Development Tools 15-SP2 (src): go1.17-1.17.2-1.6.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1420-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1182345,1191468 CVE References: CVE-2021-38297 JIRA References: Sources used: openSUSE Leap 15.2 (src): go1.16-1.16.9-lp152.14.1
donehttps://smash.suse.de/issue/314248/
SUSE-SU-2023:0603-1: An update that solves two vulnerabilities and has four fixes can now be installed. Category: security (important) Bug References: 1191468, 1195391, 1195838, 1202100, 1202101, 1208723 CVE References: CVE-2021-38297, CVE-2022-23806 Sources used: Public Cloud Module 12 (src): google-guest-agent-20230221.00-1.29.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0602-1: An update that solves two vulnerabilities and has one fix can now be installed. Category: security (important) Bug References: 1191468, 1195838, 1208723 CVE References: CVE-2021-38297, CVE-2022-23806 Sources used: openSUSE Leap 15.4 (src): google-osconfig-agent-20230222.00-150000.1.27.1 Public Cloud Module 15-SP1 (src): google-osconfig-agent-20230222.00-150000.1.27.1 Public Cloud Module 15-SP2 (src): google-osconfig-agent-20230222.00-150000.1.27.1 Public Cloud Module 15-SP3 (src): google-osconfig-agent-20230222.00-150000.1.27.1 Public Cloud Module 15-SP4 (src): google-osconfig-agent-20230222.00-150000.1.27.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0601-1: An update that solves two vulnerabilities and has six fixes can now be installed. Category: security (important) Bug References: 1191468, 1194319, 1195391, 1195838, 1202100, 1202101, 1202826, 1208723 CVE References: CVE-2021-38297, CVE-2022-23806 Sources used: Public Cloud Module 12 (src): google-osconfig-agent-20230222.00-1.20.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0600-1: An update that solves two vulnerabilities and has two fixes can now be installed. Category: security (important) Bug References: 1191468, 1195391, 1195838, 1208723 CVE References: CVE-2021-38297, CVE-2022-23806 Sources used: openSUSE Leap 15.4 (src): google-guest-agent-20230221.00-150000.1.34.1 Public Cloud Module 15-SP1 (src): google-guest-agent-20230221.00-150000.1.34.1 Public Cloud Module 15-SP2 (src): google-guest-agent-20230221.00-150000.1.34.1 Public Cloud Module 15-SP3 (src): google-guest-agent-20230221.00-150000.1.34.1 Public Cloud Module 15-SP4 (src): google-guest-agent-20230221.00-150000.1.34.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.