File _patchinfo of Package patchinfo.31912
<patchinfo incident="31912">
<issue tracker="bnc" id="1216943">VUL-0: CVE-2023-45283: go1.20,go1.21: path/filepath: recognize \??\ as a Root Local Device path prefix</issue>
<issue tracker="bnc" id="1217833">VUL-0: CVE-2023-39326: go1.20,go1.21: net/http: limit chunked data overhead</issue>
<issue tracker="bnc" id="1217834">VUL-0: CVE-2023-45285: go1.20,go1.21: cmd/go: go get may unexpectedly fallback to insecure git</issue>
<issue tracker="bnc" id="1212475">go1.21 release tracking</issue>
<issue tracker="cve" id="2023-45285"/>
<issue tracker="cve" id="2023-45284"/>
<issue tracker="cve" id="2023-39326"/>
<packager>jfkw</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for go1.21-openssl</summary>
<description>This update for go1.21-openssl fixes the following issues:
Update to version 1.21.5.1:
- CVE-2023-45285: cmd/go: git VCS qualifier in module path uses git:// scheme (bsc#1217834).
- CVE-2023-45284: path/filepath: Clean removes ending slash for volume on Windows in Go 1.21.4 (bsc#1216943).
- CVE-2023-39326: net/http: limit chunked data overhead (bsc#1217833).
- cmd/go: go mod download needs to support toolchain upgrades
- cmd/compile: invalid pointer found on stack when compiled with -race
- os: NTFS deduped file changed from regular to irregular
- net: TCPConn.ReadFrom hangs when io.Reader is TCPConn or UnixConn, Linux kernel < 5.1
- cmd/compile: internal compiler error: panic during prove while compiling: unexpected induction with too many parents
- syscall: TestOpenFileLimit unintentionally runs on non-Unix platforms
- runtime: self-deadlock on mheap_.lock
- crypto/rand: Legacy RtlGenRandom use on Windows
</description>
</patchinfo>