Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2020:4214 - Security Advisory
Issued:
2020-10-08
Updated:
2020-10-08

RHSA-2020:4214 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: go-toolset-1.13-golang security and bug fix update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for go-toolset-1.13 and go-toolset-1.13-golang is now available for Red Hat Developer Tools.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)
  • golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586)
  • golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • net/http, x/net/http2: http server shutdown doesn't gracefully shut down HTTP2 connections (BZ#1879236)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Developer Tools (for RHEL Workstation) 1 x86_64
  • Red Hat Developer Tools (for RHEL Server) 1 x86_64
  • Red Hat Developer Tools (for RHEL Server for System Z) 1 s390x
  • Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1 ppc64le

Fixes

  • BZ - 1853652 - CVE-2020-14040 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
  • BZ - 1856953 - CVE-2020-15586 golang: data race in certain net/http servers including ReverseProxy can lead to DoS
  • BZ - 1867099 - CVE-2020-16845 golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs

CVEs

  • CVE-2020-14040
  • CVE-2020-15586
  • CVE-2020-16845

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_developer_tools/1/html/using_go_1.13_toolset/
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Developer Tools (for RHEL Workstation) 1

SRPM
go-toolset-1.13-1.13.15-1.el7.src.rpm SHA-256: 7f41387d0fe19cfb8bfc46a4ac797032c440662d892ffd6e0675b72a7db5cef2
go-toolset-1.13-golang-1.13.15-3.el7.src.rpm SHA-256: d9d291a0098450e4c410d7ba463f55383c8033e69ece9f4d72e37516d89dff8d
x86_64
go-toolset-1.13-1.13.15-1.el7.x86_64.rpm SHA-256: 1a83b813e859aa9a3b3539818757698df75a76d5d9a8a6420830f98fe3d8f328
go-toolset-1.13-build-1.13.15-1.el7.x86_64.rpm SHA-256: 63c380870f13c8b80befc333e37d7ab8d19808dc284da068de8c9e66bd9ded55
go-toolset-1.13-golang-1.13.15-3.el7.x86_64.rpm SHA-256: 85eac929a4651110c31335ee01c6d20c53c4df6522f70da228ff4be3780402cb
go-toolset-1.13-golang-bin-1.13.15-3.el7.x86_64.rpm SHA-256: 29b4133d20c816a4e12f832bc120faa96928edfb1b8fb3631a4a1047cdda73b0
go-toolset-1.13-golang-docs-1.13.15-3.el7.noarch.rpm SHA-256: 7ceae26a201c7c1ddf273864e82b061ec2dacae230040f2cb5dfea439cb57b86
go-toolset-1.13-golang-misc-1.13.15-3.el7.x86_64.rpm SHA-256: e3c2923de592821f73e2b841f2eb9ecf8c6788e710aa5f5d8c190b51384e04cf
go-toolset-1.13-golang-race-1.13.15-3.el7.x86_64.rpm SHA-256: c3fbc2e448d63d5a6af949dd8317b5e483159a66b7696de4db10715bd8656195
go-toolset-1.13-golang-src-1.13.15-3.el7.x86_64.rpm SHA-256: c8dea4518408570fe7fcaedb396d7126ab920665ebf1d3eb7bea973ed6972926
go-toolset-1.13-golang-tests-1.13.15-3.el7.x86_64.rpm SHA-256: db3dac667335f7c9e6fb10c43e9d0b2305da97a998c77b1285e6e09f13f63a1c
go-toolset-1.13-runtime-1.13.15-1.el7.x86_64.rpm SHA-256: b041162d1f1e415f7fd4e6e814990578fb9480ef3069e341b8fa1b6b706366e3

Red Hat Developer Tools (for RHEL Server) 1

SRPM
go-toolset-1.13-1.13.15-1.el7.src.rpm SHA-256: 7f41387d0fe19cfb8bfc46a4ac797032c440662d892ffd6e0675b72a7db5cef2
go-toolset-1.13-golang-1.13.15-3.el7.src.rpm SHA-256: d9d291a0098450e4c410d7ba463f55383c8033e69ece9f4d72e37516d89dff8d
x86_64
go-toolset-1.13-1.13.15-1.el7.x86_64.rpm SHA-256: 1a83b813e859aa9a3b3539818757698df75a76d5d9a8a6420830f98fe3d8f328
go-toolset-1.13-build-1.13.15-1.el7.x86_64.rpm SHA-256: 63c380870f13c8b80befc333e37d7ab8d19808dc284da068de8c9e66bd9ded55
go-toolset-1.13-golang-1.13.15-3.el7.x86_64.rpm SHA-256: 85eac929a4651110c31335ee01c6d20c53c4df6522f70da228ff4be3780402cb
go-toolset-1.13-golang-bin-1.13.15-3.el7.x86_64.rpm SHA-256: 29b4133d20c816a4e12f832bc120faa96928edfb1b8fb3631a4a1047cdda73b0
go-toolset-1.13-golang-docs-1.13.15-3.el7.noarch.rpm SHA-256: 7ceae26a201c7c1ddf273864e82b061ec2dacae230040f2cb5dfea439cb57b86
go-toolset-1.13-golang-misc-1.13.15-3.el7.x86_64.rpm SHA-256: e3c2923de592821f73e2b841f2eb9ecf8c6788e710aa5f5d8c190b51384e04cf
go-toolset-1.13-golang-race-1.13.15-3.el7.x86_64.rpm SHA-256: c3fbc2e448d63d5a6af949dd8317b5e483159a66b7696de4db10715bd8656195
go-toolset-1.13-golang-src-1.13.15-3.el7.x86_64.rpm SHA-256: c8dea4518408570fe7fcaedb396d7126ab920665ebf1d3eb7bea973ed6972926
go-toolset-1.13-golang-tests-1.13.15-3.el7.x86_64.rpm SHA-256: db3dac667335f7c9e6fb10c43e9d0b2305da97a998c77b1285e6e09f13f63a1c
go-toolset-1.13-runtime-1.13.15-1.el7.x86_64.rpm SHA-256: b041162d1f1e415f7fd4e6e814990578fb9480ef3069e341b8fa1b6b706366e3

Red Hat Developer Tools (for RHEL Server for System Z) 1

SRPM
go-toolset-1.13-1.13.15-1.el7.src.rpm SHA-256: 7f41387d0fe19cfb8bfc46a4ac797032c440662d892ffd6e0675b72a7db5cef2
go-toolset-1.13-golang-1.13.15-3.el7.src.rpm SHA-256: d9d291a0098450e4c410d7ba463f55383c8033e69ece9f4d72e37516d89dff8d
s390x
go-toolset-1.13-1.13.15-1.el7.s390x.rpm SHA-256: 3f8ce8ae00b5bed18f92c2c68d58f115e3ede269cac6283d06b5e0f2b3f6c455
go-toolset-1.13-build-1.13.15-1.el7.s390x.rpm SHA-256: ef8b81b7a7548374ee8d296fcb4a8fd242fb36a1591578962f9fb019686461da
go-toolset-1.13-golang-1.13.15-3.el7.s390x.rpm SHA-256: 6f5a43145f25020eeabffa3ce44ecebcd3dc5da9a1c1104837e305f3e1967dff
go-toolset-1.13-golang-bin-1.13.15-3.el7.s390x.rpm SHA-256: 9770c053a3ca20c533c0ef0d0ac43b11a3937cf888c2a4306469b2cb119aaa3b
go-toolset-1.13-golang-docs-1.13.15-3.el7.noarch.rpm SHA-256: 7ceae26a201c7c1ddf273864e82b061ec2dacae230040f2cb5dfea439cb57b86
go-toolset-1.13-golang-misc-1.13.15-3.el7.s390x.rpm SHA-256: 2d7623963f0b9f581f7e09030c96a78fd3464d6253969fc5eb3af4b31b36d881
go-toolset-1.13-golang-src-1.13.15-3.el7.s390x.rpm SHA-256: 6f812739942d233131721178d7a04d3ebe8088358bdda94eb7cba2818ecd66d1
go-toolset-1.13-golang-tests-1.13.15-3.el7.s390x.rpm SHA-256: 595b690833c2e1b69ceaaa534da169e37238059c10db4c4f7e20a54fdb017b9f
go-toolset-1.13-runtime-1.13.15-1.el7.s390x.rpm SHA-256: 67d80b534b7c8d53741119c9049c8c7ef211a0de1199d55e1e73bac856257ef5

Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1

SRPM
go-toolset-1.13-1.13.15-1.el7.src.rpm SHA-256: 7f41387d0fe19cfb8bfc46a4ac797032c440662d892ffd6e0675b72a7db5cef2
go-toolset-1.13-golang-1.13.15-3.el7.src.rpm SHA-256: d9d291a0098450e4c410d7ba463f55383c8033e69ece9f4d72e37516d89dff8d
ppc64le
go-toolset-1.13-1.13.15-1.el7.ppc64le.rpm SHA-256: d68c8e7d389d36be066daac7ebe1b4e9af463bd46c7e7d2781c9e3c0fb1d67c5
go-toolset-1.13-build-1.13.15-1.el7.ppc64le.rpm SHA-256: 5e25780187557abf3de1e203d03eb2ac5e463a614301ad5c0c395a3624511f82
go-toolset-1.13-golang-1.13.15-3.el7.ppc64le.rpm SHA-256: 8b027fad9d0df4c32393b106f080cb94d8eb84b4e07eb30b922184a8cd26eb70
go-toolset-1.13-golang-bin-1.13.15-3.el7.ppc64le.rpm SHA-256: 19335abc4164496d91af39f2ac96b7109e57a07f3a076e2637846dbc032c0db1
go-toolset-1.13-golang-docs-1.13.15-3.el7.noarch.rpm SHA-256: 7ceae26a201c7c1ddf273864e82b061ec2dacae230040f2cb5dfea439cb57b86
go-toolset-1.13-golang-misc-1.13.15-3.el7.ppc64le.rpm SHA-256: 403f6b5bc3b1b8885a5e307cbb4eeca1dc21c400f383a3921f8a82b8e11dbb1d
go-toolset-1.13-golang-src-1.13.15-3.el7.ppc64le.rpm SHA-256: 44d2dfb087f349fc3dd8747755f2c3c48e4f18baeb1e7f17af8c1cbc7366bca4
go-toolset-1.13-golang-tests-1.13.15-3.el7.ppc64le.rpm SHA-256: 6dbe5b1851c257c71b7d87905362bd43a5b8734774e9c00927a571bb1472900e
go-toolset-1.13-runtime-1.13.15-1.el7.ppc64le.rpm SHA-256: a646e76786be6ed7cdb0267ec43f0f5f324ee8dd0eaf76515f43b81c8bd953e9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter