File _patchinfo of Package patchinfo.28155
<patchinfo incident="28155">
<issue tracker="bnc" id="1200441">go1.19 release tracking</issue>
<issue tracker="bnc" id="1209030">VUL-0: CVE-2023-24532: go1.19,go1.20: crypto/elliptic: incorrect P-256 ScalarMult and ScalarBaseMult results</issue>
<issue tracker="cve" id="2023-24532"/>
<packager>jfkw</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for go1.19</summary>
<description>This update for go1.19 fixes the following issues:
- CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1200441).
Update to go1.19.7 (released 2023-03-07) includes a security fix to the
* go#58719 go#58647 bsc#1209030 security: fix CVE-2023-24532 crypto/elliptic: specific unreduced P-256 scalars produce incorrect results
* go#58441 runtime: some linkname signatures do not match
* go#58502 cmd/link: relocation truncated to fit: R_ARM_CALL against `runtime.duffcopy'
* go#58535 runtime: long latency of sweep assists
* go#58716 net: TestTCPSelfConnect failures due to unexpected connections
* go#58773 syscall: Environ uses an invalid unsafe.Pointer conversion on Windows
* go#58810 crypto/x509: TestSystemVerify consistently failing
</description>
</patchinfo>