Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2021:3015 - Security Advisory
Issued:
2021-08-05
Updated:
2021-08-05

RHSA-2021:3015 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: go-toolset-1.15 and go-toolset-1.15-golang security and bug fix update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for go-toolset-1.15 and go-toolset-1.15-golang is now available for Red Hat Developer Tools.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

The go-toolset packages have been updated to version 1.15.14. (BZ#1982664)

Security Fix(es):

  • golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • FIPS mode AES CBC CryptBlocks incorrectly re-initializes IV in file crypto/internal/boring/aes.go (BZ#1978557)

For details, see Using Go Toolset linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Developer Tools (for RHEL Workstation) 1 x86_64
  • Red Hat Developer Tools (for RHEL Server) 1 x86_64
  • Red Hat Developer Tools (for RHEL Server for System Z) 1 s390x
  • Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1 ppc64le

Fixes

  • BZ - 1983596 - CVE-2021-34558 golang: crypto/tls: certificate of wrong type is causing TLS client to panic

CVEs

  • CVE-2021-34558

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_developer_tools/1/html/using_go_1.15.7_toolset
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Developer Tools (for RHEL Workstation) 1

SRPM
go-toolset-1.15-1.15.14-1.el7_9.src.rpm SHA-256: c87e69e7a1090d0997aee99aa8ebe62a0e74df703946dadd5bebfb52f061fffc
go-toolset-1.15-golang-1.15.14-1.el7_9.src.rpm SHA-256: fb0a153c8ce8d3ce656c8d0a91d31bb62e4b6809a9c2ae756866f480498f2261
x86_64
go-toolset-1.15-1.15.14-1.el7_9.x86_64.rpm SHA-256: ed4757a19038c5f09158625a2c85b3316ad9148a23a7f039463abb07f663ca75
go-toolset-1.15-build-1.15.14-1.el7_9.x86_64.rpm SHA-256: ea2619c2946cfd1e8f456930da212d2b02ecf033ed0a46433693aafccd4ba6a9
go-toolset-1.15-golang-1.15.14-1.el7_9.x86_64.rpm SHA-256: 123cee6372ec8589e115980bb844f8c3dade88281d085120005f8528a47f7503
go-toolset-1.15-golang-bin-1.15.14-1.el7_9.x86_64.rpm SHA-256: 7d1bd78eaaa284af30745040498553451416c5736b3db24829a8fccf1e05bfe1
go-toolset-1.15-golang-docs-1.15.14-1.el7_9.noarch.rpm SHA-256: 9833ffaf9fde98b533e101e881bc525683152aac920fa2fa470db5644579a5ae
go-toolset-1.15-golang-misc-1.15.14-1.el7_9.x86_64.rpm SHA-256: 0c65be363cee1fd8f613153fc3f839c045ab7f223f3250c614c114b137482441
go-toolset-1.15-golang-race-1.15.14-1.el7_9.x86_64.rpm SHA-256: 691a96f48ae13a5644b6cd3f06d7dd657d8a84587417a2f8aa7f68e71a130a2e
go-toolset-1.15-golang-src-1.15.14-1.el7_9.x86_64.rpm SHA-256: 8fe8fb9670d0f7bb62ba67456fffc9ed58876330bcce833e47a86ccf72afed8f
go-toolset-1.15-golang-tests-1.15.14-1.el7_9.x86_64.rpm SHA-256: da0d416a20f936d643f20fba4554650d6845bad20a5157948ce7a2adfadd1b1a
go-toolset-1.15-runtime-1.15.14-1.el7_9.x86_64.rpm SHA-256: 0b99447084d9a9db79339c12fd633dc664fcd7c61bfe414ee55829718077cae4
go-toolset-1.15-scldevel-1.15.14-1.el7_9.x86_64.rpm SHA-256: 52ee213ca8df48739578abc6dccfbdb56e686a1af532a81e4051ed895ca6405e

Red Hat Developer Tools (for RHEL Server) 1

SRPM
go-toolset-1.15-1.15.14-1.el7_9.src.rpm SHA-256: c87e69e7a1090d0997aee99aa8ebe62a0e74df703946dadd5bebfb52f061fffc
go-toolset-1.15-golang-1.15.14-1.el7_9.src.rpm SHA-256: fb0a153c8ce8d3ce656c8d0a91d31bb62e4b6809a9c2ae756866f480498f2261
x86_64
go-toolset-1.15-1.15.14-1.el7_9.x86_64.rpm SHA-256: ed4757a19038c5f09158625a2c85b3316ad9148a23a7f039463abb07f663ca75
go-toolset-1.15-build-1.15.14-1.el7_9.x86_64.rpm SHA-256: ea2619c2946cfd1e8f456930da212d2b02ecf033ed0a46433693aafccd4ba6a9
go-toolset-1.15-golang-1.15.14-1.el7_9.x86_64.rpm SHA-256: 123cee6372ec8589e115980bb844f8c3dade88281d085120005f8528a47f7503
go-toolset-1.15-golang-bin-1.15.14-1.el7_9.x86_64.rpm SHA-256: 7d1bd78eaaa284af30745040498553451416c5736b3db24829a8fccf1e05bfe1
go-toolset-1.15-golang-docs-1.15.14-1.el7_9.noarch.rpm SHA-256: 9833ffaf9fde98b533e101e881bc525683152aac920fa2fa470db5644579a5ae
go-toolset-1.15-golang-misc-1.15.14-1.el7_9.x86_64.rpm SHA-256: 0c65be363cee1fd8f613153fc3f839c045ab7f223f3250c614c114b137482441
go-toolset-1.15-golang-race-1.15.14-1.el7_9.x86_64.rpm SHA-256: 691a96f48ae13a5644b6cd3f06d7dd657d8a84587417a2f8aa7f68e71a130a2e
go-toolset-1.15-golang-src-1.15.14-1.el7_9.x86_64.rpm SHA-256: 8fe8fb9670d0f7bb62ba67456fffc9ed58876330bcce833e47a86ccf72afed8f
go-toolset-1.15-golang-tests-1.15.14-1.el7_9.x86_64.rpm SHA-256: da0d416a20f936d643f20fba4554650d6845bad20a5157948ce7a2adfadd1b1a
go-toolset-1.15-runtime-1.15.14-1.el7_9.x86_64.rpm SHA-256: 0b99447084d9a9db79339c12fd633dc664fcd7c61bfe414ee55829718077cae4
go-toolset-1.15-scldevel-1.15.14-1.el7_9.x86_64.rpm SHA-256: 52ee213ca8df48739578abc6dccfbdb56e686a1af532a81e4051ed895ca6405e

Red Hat Developer Tools (for RHEL Server for System Z) 1

SRPM
go-toolset-1.15-1.15.14-1.el7_9.src.rpm SHA-256: c87e69e7a1090d0997aee99aa8ebe62a0e74df703946dadd5bebfb52f061fffc
go-toolset-1.15-golang-1.15.14-1.el7_9.src.rpm SHA-256: fb0a153c8ce8d3ce656c8d0a91d31bb62e4b6809a9c2ae756866f480498f2261
s390x
go-toolset-1.15-1.15.14-1.el7_9.s390x.rpm SHA-256: 4a67128c5ed88177999f950fd545faf6ad49c675291354e6951779c13ac34b32
go-toolset-1.15-build-1.15.14-1.el7_9.s390x.rpm SHA-256: af4e2ea742ba91f44db945cbd91d7c7c7cfe190cdd636d3841ae91f072742578
go-toolset-1.15-golang-1.15.14-1.el7_9.s390x.rpm SHA-256: 47827c4c8548c88cf84aa4e1a6ba0d8c36eeb11debb03ffb3a14ac02663c6fac
go-toolset-1.15-golang-bin-1.15.14-1.el7_9.s390x.rpm SHA-256: b2da7254b81963d2d67a3635ad09755175627dc64a4498cac20e6ba394c69837
go-toolset-1.15-golang-docs-1.15.14-1.el7_9.noarch.rpm SHA-256: 9833ffaf9fde98b533e101e881bc525683152aac920fa2fa470db5644579a5ae
go-toolset-1.15-golang-misc-1.15.14-1.el7_9.s390x.rpm SHA-256: e5437f50179f7ce1bac0f5283d81c0568a842d067ab9e5796a7e527ee7c584d1
go-toolset-1.15-golang-src-1.15.14-1.el7_9.s390x.rpm SHA-256: cb67e050934a70384736cbda2be545a70ac337a0e2f1fe5b6985226297f3d0b6
go-toolset-1.15-golang-tests-1.15.14-1.el7_9.s390x.rpm SHA-256: 362ccee3ca809a119034ed92ba643e1a6bb56511aa7a17997655fc50d04cc0c4
go-toolset-1.15-runtime-1.15.14-1.el7_9.s390x.rpm SHA-256: 38674192fcf52201f40a13a6ec797a3d4e00129a048c839d74a896520771a222
go-toolset-1.15-scldevel-1.15.14-1.el7_9.s390x.rpm SHA-256: 9e2d11c959b8c33988f8d1b01bf72829d8ead1bdd33b68ed0ee2160045fed6e0

Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1

SRPM
go-toolset-1.15-1.15.14-1.el7_9.src.rpm SHA-256: c87e69e7a1090d0997aee99aa8ebe62a0e74df703946dadd5bebfb52f061fffc
go-toolset-1.15-golang-1.15.14-1.el7_9.src.rpm SHA-256: fb0a153c8ce8d3ce656c8d0a91d31bb62e4b6809a9c2ae756866f480498f2261
ppc64le
go-toolset-1.15-1.15.14-1.el7_9.ppc64le.rpm SHA-256: 3fe15166b841f9254ec8406a613bfab2b49544f91cd6bb6bee9cdca7863e055e
go-toolset-1.15-build-1.15.14-1.el7_9.ppc64le.rpm SHA-256: 3e2e728763375de107a347103e36cc9b86a4c9b8e11cca6c547493c6ad1231e2
go-toolset-1.15-golang-1.15.14-1.el7_9.ppc64le.rpm SHA-256: 6001f3b555647d137f3bafd5f5eb602cd2f8367daba4813e7400f800934aff6e
go-toolset-1.15-golang-bin-1.15.14-1.el7_9.ppc64le.rpm SHA-256: 19fc26c25d0e2ca3de6cb24c50d3e124fce1a51df0152f9f25bb0010a833b759
go-toolset-1.15-golang-docs-1.15.14-1.el7_9.noarch.rpm SHA-256: 9833ffaf9fde98b533e101e881bc525683152aac920fa2fa470db5644579a5ae
go-toolset-1.15-golang-misc-1.15.14-1.el7_9.ppc64le.rpm SHA-256: 9f88f203cbdc4a602a649d1d40a3f95ae7ac001cc0ecb6f68fcb5825c72fc1e9
go-toolset-1.15-golang-src-1.15.14-1.el7_9.ppc64le.rpm SHA-256: 3dee7da40a3dc444a75892bcaf1e5c2c6c36444572828023d2070ced9fadf9cc
go-toolset-1.15-golang-tests-1.15.14-1.el7_9.ppc64le.rpm SHA-256: 67c1e52e5e2cc01e7292703ea5e1eacacca011cd4a1a96e62fd53b45e3a134fe
go-toolset-1.15-runtime-1.15.14-1.el7_9.ppc64le.rpm SHA-256: ec1dc8916bba447524af7e5428ca3f30985d7e41e637f61dea57d2cea9f97f32
go-toolset-1.15-scldevel-1.15.14-1.el7_9.ppc64le.rpm SHA-256: 6a04001cfaa8ee33387ea81ef304ed25b5fbd1a2e8616c124059958aab6e54bd

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility