Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[20.10 backport] Update Go to 1.16.10 #3358

Merged
merged 1 commit into from
Nov 17, 2021

Conversation

thaJeztah
Copy link
Member

backport of #3357

go1.16.10 (released 2021-11-04) includes security fixes to the archive/zip and
debug/macho packages, as well as bug fixes to the compiler, linker, runtime, the
misc/wasm directory, and to the net/http package. See the Go 1.16.10 milestone
for details: https://github.com/golang/go/issues?q=milestone%3AGo1.16.10+label%3ACherryPickApproved

From the announcement e-mail:

[security] Go 1.17.3 and Go 1.16.10 are released

We have just released Go versions 1.17.3 and 1.16.10, minor point releases.
These minor releases include two security fixes following the security policy:

  • archive/zip: don't panic on (*Reader).Open
    Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made
    to panic by an attacker providing either a crafted ZIP archive containing
    completely invalid names or an empty filename argument.
    Thank you to Colin Arnott, SiteHost and Noah Santschi-Cooney, Sourcegraph Code
    Intelligence Team for reporting this issue. This is CVE-2021-41772 and Go issue
    golang.org/issue/48085.
  • debug/macho: invalid dynamic symbol table command can cause panic
    Malformed binaries parsed using Open or OpenFat can cause a panic when calling
    ImportedSymbols, due to an out-of-bounds slice operation.
    Thanks to Burak Çarıkçı - Yunus Yıldırım (CT-Zer0 Crypttech) for reporting this
    issue. This is CVE-2021-41771 and Go issue golang.org/issue/48990.

- Description for the changelog

- A picture of a cute animal (not mandatory but encouraged)

go1.16.10 (released 2021-11-04) includes security fixes to the archive/zip and
debug/macho packages, as well as bug fixes to the compiler, linker, runtime, the
misc/wasm directory, and to the net/http package. See the Go 1.16.10 milestone
for details: https://github.com/golang/go/issues?q=milestone%3AGo1.16.10+label%3ACherryPickApproved

From the announcement e-mail:

[security] Go 1.17.3 and Go 1.16.10 are released

We have just released Go versions 1.17.3 and 1.16.10, minor point releases.
These minor releases include two security fixes following the security policy:

- archive/zip: don't panic on (*Reader).Open
  Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made
  to panic by an attacker providing either a crafted ZIP archive containing
  completely invalid names or an empty filename argument.
  Thank you to Colin Arnott, SiteHost and Noah Santschi-Cooney, Sourcegraph Code
  Intelligence Team for reporting this issue. This is CVE-2021-41772 and Go issue
  golang.org/issue/48085.
- debug/macho: invalid dynamic symbol table command can cause panic
  Malformed binaries parsed using Open or OpenFat can cause a panic when calling
  ImportedSymbols, due to an out-of-bounds slice operation.
  Thanks to Burak Çarıkçı - Yunus Yıldırım (CT-Zer0 Crypttech) for reporting this
  issue. This is CVE-2021-41771 and Go issue golang.org/issue/48990.

Signed-off-by: Sebastiaan van Stijn <[email protected]>
(cherry picked from commit e285f15)
Signed-off-by: Sebastiaan van Stijn <[email protected]>
@codecov-commenter
Copy link

Codecov Report

Merging #3358 (03fa8f9) into 20.10 (b485636) will not change coverage.
The diff coverage is n/a.

@@           Coverage Diff           @@
##            20.10    #3358   +/-   ##
=======================================
  Coverage   58.57%   58.57%           
=======================================
  Files         299      299           
  Lines       21454    21454           
=======================================
  Hits        12566    12566           
  Misses       7970     7970           
  Partials      918      918           

@thaJeztah
Copy link
Member Author

@thaJeztah thaJeztah merged commit dea9396 into docker:20.10 Nov 17, 2021
@thaJeztah thaJeztah deleted the 20.10_backport_bump_go_1.16.10 branch November 17, 2021 23:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants