Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:5333 - Security Advisory
Issued:
2020-12-03
Updated:
2020-12-03

RHSA-2020:5333 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: go-toolset-1.14-golang security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for go-toolset-1.14-golang is now available for Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • golang: math/big: panic during recursive division of very large numbers (CVE-2020-28362)
  • golang: malicious symbol names can lead to code execution at build time (CVE-2020-28366)
  • golang: improper validation of cgo flags can lead to code execution at build time (CVE-2020-28367)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Developer Tools (for RHEL Server) 1 x86_64
  • Red Hat Developer Tools (for RHEL Workstation) 1 x86_64
  • Red Hat Developer Tools (for RHEL Server for System Z) 1 s390x
  • Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1 ppc64le

Fixes

  • BZ - 1897635 - CVE-2020-28362 golang: math/big: panic during recursive division of very large numbers
  • BZ - 1897643 - CVE-2020-28366 golang: malicious symbol names can lead to code execution at build time
  • BZ - 1897646 - CVE-2020-28367 golang: improper validation of cgo flags can lead to code execution at build time

CVEs

  • CVE-2020-28362
  • CVE-2020-28366
  • CVE-2020-28367

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_developer_tools/1/html/using_go_1.14.7_toolset
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Developer Tools (for RHEL Server) 1

SRPM
go-toolset-1.14-1.14.12-1.el7_9.src.rpm SHA-256: 90690e238c41b604aa531021a05898b997fb2c210b98599c8e36e44ee5562e8b
go-toolset-1.14-golang-1.14.12-1.el7_9.src.rpm SHA-256: 6234425ebd1711bef7fcf3625475eeec03bfd7abffd431e286b821cb86b9105b
x86_64
go-toolset-1.14-1.14.12-1.el7_9.x86_64.rpm SHA-256: 20be3c387bddc0de303c4b8b4eabc7e2b7985975265656f33f9260e472dc4274
go-toolset-1.14-build-1.14.12-1.el7_9.x86_64.rpm SHA-256: 8c04ca4e753377f11ffac4852520fb0e98de395a7c22486e32db5b2c82c6a106
go-toolset-1.14-golang-1.14.12-1.el7_9.x86_64.rpm SHA-256: 30f69643fe706e60aef53dc8ccd72a1a000678c7eda8194b73bdb537d5382c66
go-toolset-1.14-golang-bin-1.14.12-1.el7_9.x86_64.rpm SHA-256: a3aa97bb8f98511cd06c278677b220175daadbbffa3535a0565e922da8b73c78
go-toolset-1.14-golang-docs-1.14.12-1.el7_9.noarch.rpm SHA-256: 5f1b7812965d9df183028ed934d0a6bba6bc6ca8732a4f9217d974b761d444e6
go-toolset-1.14-golang-misc-1.14.12-1.el7_9.x86_64.rpm SHA-256: 52eb69fd9fbc82035e4093c11bda22d70554567262eaac0a235e4c6ebba83d75
go-toolset-1.14-golang-race-1.14.12-1.el7_9.x86_64.rpm SHA-256: 21e141b406f0f6073487545cfe2d056586993c420497aadbd56352f070f45cae
go-toolset-1.14-golang-src-1.14.12-1.el7_9.x86_64.rpm SHA-256: 6be362f599338f9a2c011c9c8f6c2e5a9dc72c2f9c5f38bbcabd336c4c060aa7
go-toolset-1.14-golang-tests-1.14.12-1.el7_9.x86_64.rpm SHA-256: a96a16d826d2e8e1bdfe147dbffc184c2940f117dc8ff83ccb30e7b1abc4b301
go-toolset-1.14-runtime-1.14.12-1.el7_9.x86_64.rpm SHA-256: 293f895d1b0372eaa5d86a955bdd737195708c18c5ee8975fbf40c111adff762

Red Hat Developer Tools (for RHEL Workstation) 1

SRPM
go-toolset-1.14-1.14.12-1.el7_9.src.rpm SHA-256: 90690e238c41b604aa531021a05898b997fb2c210b98599c8e36e44ee5562e8b
go-toolset-1.14-golang-1.14.12-1.el7_9.src.rpm SHA-256: 6234425ebd1711bef7fcf3625475eeec03bfd7abffd431e286b821cb86b9105b
x86_64
go-toolset-1.14-1.14.12-1.el7_9.x86_64.rpm SHA-256: 20be3c387bddc0de303c4b8b4eabc7e2b7985975265656f33f9260e472dc4274
go-toolset-1.14-build-1.14.12-1.el7_9.x86_64.rpm SHA-256: 8c04ca4e753377f11ffac4852520fb0e98de395a7c22486e32db5b2c82c6a106
go-toolset-1.14-golang-1.14.12-1.el7_9.x86_64.rpm SHA-256: 30f69643fe706e60aef53dc8ccd72a1a000678c7eda8194b73bdb537d5382c66
go-toolset-1.14-golang-bin-1.14.12-1.el7_9.x86_64.rpm SHA-256: a3aa97bb8f98511cd06c278677b220175daadbbffa3535a0565e922da8b73c78
go-toolset-1.14-golang-docs-1.14.12-1.el7_9.noarch.rpm SHA-256: 5f1b7812965d9df183028ed934d0a6bba6bc6ca8732a4f9217d974b761d444e6
go-toolset-1.14-golang-misc-1.14.12-1.el7_9.x86_64.rpm SHA-256: 52eb69fd9fbc82035e4093c11bda22d70554567262eaac0a235e4c6ebba83d75
go-toolset-1.14-golang-race-1.14.12-1.el7_9.x86_64.rpm SHA-256: 21e141b406f0f6073487545cfe2d056586993c420497aadbd56352f070f45cae
go-toolset-1.14-golang-src-1.14.12-1.el7_9.x86_64.rpm SHA-256: 6be362f599338f9a2c011c9c8f6c2e5a9dc72c2f9c5f38bbcabd336c4c060aa7
go-toolset-1.14-golang-tests-1.14.12-1.el7_9.x86_64.rpm SHA-256: a96a16d826d2e8e1bdfe147dbffc184c2940f117dc8ff83ccb30e7b1abc4b301
go-toolset-1.14-runtime-1.14.12-1.el7_9.x86_64.rpm SHA-256: 293f895d1b0372eaa5d86a955bdd737195708c18c5ee8975fbf40c111adff762

Red Hat Developer Tools (for RHEL Server for System Z) 1

SRPM
go-toolset-1.14-1.14.12-1.el7_9.src.rpm SHA-256: 90690e238c41b604aa531021a05898b997fb2c210b98599c8e36e44ee5562e8b
go-toolset-1.14-golang-1.14.12-1.el7_9.src.rpm SHA-256: 6234425ebd1711bef7fcf3625475eeec03bfd7abffd431e286b821cb86b9105b
s390x
go-toolset-1.14-1.14.12-1.el7_9.s390x.rpm SHA-256: 7fc6cfedf2b7f01ab84a9f043dd364b05a2aa9a77646137fbf9fd777eaadc0ca
go-toolset-1.14-build-1.14.12-1.el7_9.s390x.rpm SHA-256: c6e4a250aaaa863ceda31431fbddca32044253aa1396006f8f0b52b6f4e51a02
go-toolset-1.14-golang-1.14.12-1.el7_9.s390x.rpm SHA-256: ebf58299feb049de377057c9a5e458f2f13ee4fd7f78ce1bfdca6129fc6b7c5b
go-toolset-1.14-golang-bin-1.14.12-1.el7_9.s390x.rpm SHA-256: 9df5724ffa2ff7e1aead77ae31f0ac480d1b0a989e7e50a13d44c70dec2f5557
go-toolset-1.14-golang-docs-1.14.12-1.el7_9.noarch.rpm SHA-256: 5f1b7812965d9df183028ed934d0a6bba6bc6ca8732a4f9217d974b761d444e6
go-toolset-1.14-golang-misc-1.14.12-1.el7_9.s390x.rpm SHA-256: b4382cd822bba9fa71f5591d5092634a6e8f3263ede73ed36eb5184688117534
go-toolset-1.14-golang-src-1.14.12-1.el7_9.s390x.rpm SHA-256: 29b763cdbc028780dd61f408b7c3a8ccb1073c6fe61c94dd9c99f3099abf0254
go-toolset-1.14-golang-tests-1.14.12-1.el7_9.s390x.rpm SHA-256: 0f98cb1930a59c5d058571d2a9b10066f1621961bb4fe53b6de73451f2f9aa49
go-toolset-1.14-runtime-1.14.12-1.el7_9.s390x.rpm SHA-256: 85d7d3ce60e89bab8f93f52fed3da74a3cbb4744eb25387ce2808f8e8c66daf4

Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1

SRPM
go-toolset-1.14-1.14.12-1.el7_9.src.rpm SHA-256: 90690e238c41b604aa531021a05898b997fb2c210b98599c8e36e44ee5562e8b
go-toolset-1.14-golang-1.14.12-1.el7_9.src.rpm SHA-256: 6234425ebd1711bef7fcf3625475eeec03bfd7abffd431e286b821cb86b9105b
ppc64le
go-toolset-1.14-1.14.12-1.el7_9.ppc64le.rpm SHA-256: ff7da62ac5f5184784fef73cd95f06ae7cd1ac9aacee6fa1948c821ea76f8960
go-toolset-1.14-build-1.14.12-1.el7_9.ppc64le.rpm SHA-256: e568e27cf42e6636c5b327b62efc472966ff4b3cc9916c1f4209db13f9f78de6
go-toolset-1.14-golang-1.14.12-1.el7_9.ppc64le.rpm SHA-256: 609af4a2db44532f2781b8e07c75443da57348431a32253ecb42569a0b995f3c
go-toolset-1.14-golang-bin-1.14.12-1.el7_9.ppc64le.rpm SHA-256: e1230cf97fe70b8b09bde8821968b0ff25535602181ce8fbba79f41be71edf8f
go-toolset-1.14-golang-docs-1.14.12-1.el7_9.noarch.rpm SHA-256: 5f1b7812965d9df183028ed934d0a6bba6bc6ca8732a4f9217d974b761d444e6
go-toolset-1.14-golang-misc-1.14.12-1.el7_9.ppc64le.rpm SHA-256: e37a236450d3fdae7cfa1d7d3f928b819baa8249d144e32b00c0ae498e8062e7
go-toolset-1.14-golang-src-1.14.12-1.el7_9.ppc64le.rpm SHA-256: 5ec1fc71c7867b7c99fadaab88062101fd98a98c57a7c8cfcb7cf195edf0914c
go-toolset-1.14-golang-tests-1.14.12-1.el7_9.ppc64le.rpm SHA-256: 6ea88294172f1a4469033d4c70d4ec52dc7ea1c2ee917fcb41f6367151552e21
go-toolset-1.14-runtime-1.14.12-1.el7_9.ppc64le.rpm SHA-256: 2b006785fa08b101e66a04d364b731b1c6e6e3949b953e424d6300455953b8a7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility