go-toolset:rhel8 security update

エラータID: AXSA:2025-11505:01

リリース日: 
2025/12/10 Wednesday - 18:24
題名: 
go-toolset:rhel8 security update
影響のあるチャネル: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

* os/exec: Unexpected paths returned from LookPath in os/exec (CVE-2025-47906)
* golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-47906
If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
CVE-2025-58183
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

Modularity name: "go-toolset"
Stream name: "rhel8"

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. delve-1.25.2-1.module+el8+1925+06426c92.ML.1.src.rpm
    MD5: 3448c9681e21a4772d0569fedfc15b6f
    SHA-256: 3564789cc74a9ed30c9bf966f3e9a9a31b5457c8199636c38d710b8d96b2ef1c
    Size: 9.29 MB
  2. golang-1.25.3-2.module+el8+1925+06426c92.ML.1.src.rpm
    MD5: 819534461ef0ff030f7a62b894b16fb8
    SHA-256: 0ed2d6dec7a6f2154d486cd465e56674c469ebf178321e5ef1f5f700aa17c346
    Size: 32.77 MB
  3. go-toolset-1.24.6-1.module+el8+1925+06426c92.src.rpm
    MD5: 06ef742d7bf302056b22e8e269214ded
    SHA-256: 01435a3dff04b380b0b84a3eab877355a1ecef5e89a6920cdce21728faf0b6a8
    Size: 16.78 kB

Asianux Server 8 for x86_64
  1. delve-1.25.2-1.module+el8+1925+06426c92.ML.1.x86_64.rpm
    MD5: 255e56f862b3fbfdedf63816ab674c51
    SHA-256: d397ee093d531d1d229b9f1f728889469258ca251acd8bea7aa586f47ed89da6
    Size: 5.55 MB
  2. delve-debugsource-1.25.2-1.module+el8+1925+06426c92.ML.1.x86_64.rpm
    MD5: a6a105747721c5d3b58cbd546bb29869
    SHA-256: 17e41d607d92e56a07695f388722b91a28f1d9f249db00e7677716d6a2c483d1
    Size: 1.27 MB
  3. golang-1.25.3-2.module+el8+1925+06426c92.ML.1.x86_64.rpm
    MD5: 36434d33f5bb4b9566c443daf4553aad
    SHA-256: 93798e8fbcf34192137156a63d4fccdb6544f981d944715f10169a864afb3415
    Size: 1.34 MB
  4. golang-bin-1.25.3-2.module+el8+1925+06426c92.ML.1.x86_64.rpm
    MD5: a61cb3ebb33bd077fc547215aeebf85d
    SHA-256: 4b4f7daac95cd70b47abf3590c70bc0a3bb91dd42a2e56e860b9eaa73a42fb30
    Size: 40.13 MB
  5. golang-docs-1.25.3-2.module+el8+1925+06426c92.ML.1.noarch.rpm
    MD5: 0a6a6c8794649414863db9a74a973ab9
    SHA-256: ab766fa85b9b54c0241320129b7718b3293d2e0c02e80d2e25df6a515d8c082f
    Size: 134.63 kB
  6. golang-misc-1.25.3-2.module+el8+1925+06426c92.ML.1.noarch.rpm
    MD5: d1c96414a1a0f382f4515bbd18d5a9af
    SHA-256: 726108a85ef74994e0f1ea55104741d1c713eaf2eac7ada37b7dcdf0fa4658cc
    Size: 59.35 kB
  7. golang-race-1.25.3-2.module+el8+1925+06426c92.ML.1.x86_64.rpm
    MD5: 93a57f8ad36a4a60076ef2ce136f5c0a
    SHA-256: f0a06d7a33b33fa4222f669e23d7602e8237de2167fa5ef25ccc1e839ecef549
    Size: 1.27 MB
  8. golang-src-1.25.3-2.module+el8+1925+06426c92.ML.1.noarch.rpm
    MD5: 688ebc156dc1b75d553b53a75a94b30d
    SHA-256: e1436de901a686daa3983a9adcd9fb78d4e5965c9a3f64cb93b7a5b070bde16c
    Size: 11.56 MB
  9. golang-tests-1.25.3-2.module+el8+1925+06426c92.ML.1.noarch.rpm
    MD5: f81d19fd905734e0005a7f5513502d02
    SHA-256: fcb770ee320d55c51cda403ea8799078777e34810dae92368a25fb9ddd60bc2b
    Size: 10.77 MB
  10. go-toolset-1.24.6-1.module+el8+1925+06426c92.x86_64.rpm
    MD5: 8ae473acaf8af5793d34b78ae4cde1d3
    SHA-256: fe9ddcc944b6442d45d51b772b453610d6b21a6126e56426868f6bbb0c5decd6
    Size: 14.46 kB
  11. go-toolset-1.25.3-2.module+el8+1925+06426c92.ML.1.x86_64.rpm
    MD5: 1efd2d362b6d6980776082a216790ad0
    SHA-256: 823d11632a53a8ec0b95403197cbef5deb59433383aee655ae30988e31779c52
    Size: 32.89 kB