https://bugzilla.redhat.com/show_bug.cgi?id=2331954
Bug ID: 2331954 Summary: CVE-2024-45337 golang-x-crypto: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto [fedora-40] Product: Fedora Version: 40 Status: NEW Whiteboard: {"flaws": ["d4b62e16-e97d-4967-82ea-268c1341436b"]} Component: golang-x-crypto Keywords: Security, SecurityTracking Severity: high Priority: high Assignee: mark.e.fuller@gmx.de Reporter: ahanwate@redhat.com QA Contact: extras-qa@fedoraproject.org CC: epel-packagers-sig@lists.fedoraproject.org, go-sig@lists.fedoraproject.org, mark.e.fuller@gmx.de Blocks: 2331720 Target Milestone: --- Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2331720
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
https://bugzilla.redhat.com/show_bug.cgi?id=2331954
Fedora Update System updates@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |MODIFIED
--- Comment #1 from Fedora Update System updates@fedoraproject.org --- FEDORA-2024-8f83d0ed92 (golang-x-crypto-0.31.0-2.fc40) has been submitted as an update to Fedora 40. https://bodhi.fedoraproject.org/updates/FEDORA-2024-8f83d0ed92
https://bugzilla.redhat.com/show_bug.cgi?id=2331954
Fedora Update System updates@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|MODIFIED |ON_QA
--- Comment #2 from Fedora Update System updates@fedoraproject.org --- FEDORA-2024-8f83d0ed92 has been pushed to the Fedora 40 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-8f83d0ed92` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-8f83d0ed92
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
https://bugzilla.redhat.com/show_bug.cgi?id=2331954
Fedora Update System updates@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|ON_QA |CLOSED Resolution|--- |ERRATA Fixed In Version| |golang-x-crypto-0.31.0-2.fc | |40 Last Closed| |2024-12-16 02:29:32
--- Comment #3 from Fedora Update System updates@fedoraproject.org --- FEDORA-2024-8f83d0ed92 (golang-x-crypto-0.31.0-2.fc40) has been pushed to the Fedora 40 stable repository. If problem still persists, please make note of it in this bug report.
epel-packagers-sig@lists.fedoraproject.org