Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2022:5415 - Security Advisory
Issued:
2022-06-28
Updated:
2022-06-28

RHSA-2022:5415 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: go-toolset-1.17 and go-toolset-1.17-golang security and bug fix update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for go-toolset-1.17 and go-toolset-1.17-golang is now available for Red Hat Developer Tools.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • golang: encoding/pem: fix stack overflow in Decode (CVE-2022-24675)
  • golang: regexp: stack exhaustion via a deeply nested expression (CVE-2022-24921)
  • golang: crypto/elliptic: panic caused by oversized scalar (CVE-2022-28327)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Update to Go 1.17.10 (BZ#2091072)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Developer Tools (for RHEL Workstation) 1 x86_64
  • Red Hat Developer Tools (for RHEL Server) 1 x86_64
  • Red Hat Developer Tools (for RHEL Server for System Z) 1 s390x
  • Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1 ppc64le

Fixes

  • BZ - 2064857 - CVE-2022-24921 golang: regexp: stack exhaustion via a deeply nested expression
  • BZ - 2077688 - CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode
  • BZ - 2077689 - CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar

CVEs

  • CVE-2022-24675
  • CVE-2022-24921
  • CVE-2022-28327

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Developer Tools (for RHEL Workstation) 1

SRPM
go-toolset-1.17-1.17.10-1.el7_9.src.rpm SHA-256: 7a44f44e171bb6c26635a65e8b2e02af1e3d39123fac0611cc10e9d2b992a67b
go-toolset-1.17-golang-1.17.10-1.el7_9.src.rpm SHA-256: 7c3ec45dcb3c13c29260a04114394db4dabb352061a214638e8309de64a2629c
x86_64
go-toolset-1.17-1.17.10-1.el7_9.x86_64.rpm SHA-256: bdeb8c3b3b0bf9cc0d5edfeaaf6932af05ed6ee28a60982527f2b897e3e9a4c6
go-toolset-1.17-build-1.17.10-1.el7_9.x86_64.rpm SHA-256: e50bfa32e02d9d1f44a45262605bd6ee389a02c94c3867a6bc53eaa8400afcb5
go-toolset-1.17-golang-1.17.10-1.el7_9.x86_64.rpm SHA-256: 32e8caaa39fd72b75a447964abfd75696075bbe65680a02480ca9ed58b628ab7
go-toolset-1.17-golang-bin-1.17.10-1.el7_9.x86_64.rpm SHA-256: b933217c6148570aa6833d699f4722fa1f73b6c7ae8a163e2ac00bd672b3400f
go-toolset-1.17-golang-docs-1.17.10-1.el7_9.noarch.rpm SHA-256: b80f11db3439a3aa4252092fa45afda59257ba1de7bc11a6985b5b92ffe815f9
go-toolset-1.17-golang-misc-1.17.10-1.el7_9.x86_64.rpm SHA-256: 6bf2abd9541f725f7c4ca571aee3cb71f0e08ae87d4fc66f9971bd54dae6a01a
go-toolset-1.17-golang-race-1.17.10-1.el7_9.x86_64.rpm SHA-256: 267febeff1f8db3a776cdff35b1b62b52601b8deb29a5e73e801e6b96b326663
go-toolset-1.17-golang-src-1.17.10-1.el7_9.x86_64.rpm SHA-256: e83c55fe0bbcada427149c852d223c543d2e5bc7b09b6a137d01db2681d75fe6
go-toolset-1.17-golang-tests-1.17.10-1.el7_9.x86_64.rpm SHA-256: 960ec58a4883a2ee8418f18cfb6c47b3ed95e34a18e682b053b086d95d2d8e47
go-toolset-1.17-runtime-1.17.10-1.el7_9.x86_64.rpm SHA-256: fee3fd4619e9dbc7c7d4aaf8d501b55a98e48f86cd86b5e0c6e82bd62de44c32
go-toolset-1.17-scldevel-1.17.10-1.el7_9.x86_64.rpm SHA-256: 467dc0fe4dabe243d4a14c99f9290a69868496216641647002571ed1f877369b

Red Hat Developer Tools (for RHEL Server) 1

SRPM
go-toolset-1.17-1.17.10-1.el7_9.src.rpm SHA-256: 7a44f44e171bb6c26635a65e8b2e02af1e3d39123fac0611cc10e9d2b992a67b
go-toolset-1.17-golang-1.17.10-1.el7_9.src.rpm SHA-256: 7c3ec45dcb3c13c29260a04114394db4dabb352061a214638e8309de64a2629c
x86_64
go-toolset-1.17-1.17.10-1.el7_9.x86_64.rpm SHA-256: bdeb8c3b3b0bf9cc0d5edfeaaf6932af05ed6ee28a60982527f2b897e3e9a4c6
go-toolset-1.17-build-1.17.10-1.el7_9.x86_64.rpm SHA-256: e50bfa32e02d9d1f44a45262605bd6ee389a02c94c3867a6bc53eaa8400afcb5
go-toolset-1.17-golang-1.17.10-1.el7_9.x86_64.rpm SHA-256: 32e8caaa39fd72b75a447964abfd75696075bbe65680a02480ca9ed58b628ab7
go-toolset-1.17-golang-bin-1.17.10-1.el7_9.x86_64.rpm SHA-256: b933217c6148570aa6833d699f4722fa1f73b6c7ae8a163e2ac00bd672b3400f
go-toolset-1.17-golang-docs-1.17.10-1.el7_9.noarch.rpm SHA-256: b80f11db3439a3aa4252092fa45afda59257ba1de7bc11a6985b5b92ffe815f9
go-toolset-1.17-golang-misc-1.17.10-1.el7_9.x86_64.rpm SHA-256: 6bf2abd9541f725f7c4ca571aee3cb71f0e08ae87d4fc66f9971bd54dae6a01a
go-toolset-1.17-golang-race-1.17.10-1.el7_9.x86_64.rpm SHA-256: 267febeff1f8db3a776cdff35b1b62b52601b8deb29a5e73e801e6b96b326663
go-toolset-1.17-golang-src-1.17.10-1.el7_9.x86_64.rpm SHA-256: e83c55fe0bbcada427149c852d223c543d2e5bc7b09b6a137d01db2681d75fe6
go-toolset-1.17-golang-tests-1.17.10-1.el7_9.x86_64.rpm SHA-256: 960ec58a4883a2ee8418f18cfb6c47b3ed95e34a18e682b053b086d95d2d8e47
go-toolset-1.17-runtime-1.17.10-1.el7_9.x86_64.rpm SHA-256: fee3fd4619e9dbc7c7d4aaf8d501b55a98e48f86cd86b5e0c6e82bd62de44c32
go-toolset-1.17-scldevel-1.17.10-1.el7_9.x86_64.rpm SHA-256: 467dc0fe4dabe243d4a14c99f9290a69868496216641647002571ed1f877369b

Red Hat Developer Tools (for RHEL Server for System Z) 1

SRPM
go-toolset-1.17-1.17.10-1.el7_9.src.rpm SHA-256: 7a44f44e171bb6c26635a65e8b2e02af1e3d39123fac0611cc10e9d2b992a67b
go-toolset-1.17-golang-1.17.10-1.el7_9.src.rpm SHA-256: 7c3ec45dcb3c13c29260a04114394db4dabb352061a214638e8309de64a2629c
s390x
go-toolset-1.17-1.17.10-1.el7_9.s390x.rpm SHA-256: 52a7cdf2358bbe2813a2459a4a629f21f3a94f7160c11097fb9b9901fee21d63
go-toolset-1.17-build-1.17.10-1.el7_9.s390x.rpm SHA-256: 8445df332a14fa4ac49994fb6dbd92cb489074eda5592b4ec19d9bff31bb5e74
go-toolset-1.17-golang-1.17.10-1.el7_9.s390x.rpm SHA-256: 9727df26b9ce05b76ce4c51357b9290e8389d82e45465f30cc5937312c768206
go-toolset-1.17-golang-bin-1.17.10-1.el7_9.s390x.rpm SHA-256: 7ab8669fefe37a0d23e0021b246d307a24b33962840b8ae0151badaffdffb2de
go-toolset-1.17-golang-docs-1.17.10-1.el7_9.noarch.rpm SHA-256: b80f11db3439a3aa4252092fa45afda59257ba1de7bc11a6985b5b92ffe815f9
go-toolset-1.17-golang-misc-1.17.10-1.el7_9.s390x.rpm SHA-256: eac09d25e773d61a18e76d761d17056084cc9e0b2f9a10ca44f9d3fa71bf74a1
go-toolset-1.17-golang-src-1.17.10-1.el7_9.s390x.rpm SHA-256: 0469e66a503718e2aa769556394d65af4ab9c83d6402d7301d7463a07e3152df
go-toolset-1.17-golang-tests-1.17.10-1.el7_9.s390x.rpm SHA-256: a2b46f01354dc91ae986544691c5e423306048d0b89238cfbdccb582518792d9
go-toolset-1.17-runtime-1.17.10-1.el7_9.s390x.rpm SHA-256: f25cafd08b363011a8e1139e7dfb127e6c3aac00b70bac331ab11de6e8e7c952
go-toolset-1.17-scldevel-1.17.10-1.el7_9.s390x.rpm SHA-256: 495f05f8429cb53ec63c8612dbe843b1ec58570f8317334cdf52812fbbabd914

Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1

SRPM
go-toolset-1.17-1.17.10-1.el7_9.src.rpm SHA-256: 7a44f44e171bb6c26635a65e8b2e02af1e3d39123fac0611cc10e9d2b992a67b
go-toolset-1.17-golang-1.17.10-1.el7_9.src.rpm SHA-256: 7c3ec45dcb3c13c29260a04114394db4dabb352061a214638e8309de64a2629c
ppc64le
go-toolset-1.17-1.17.10-1.el7_9.ppc64le.rpm SHA-256: 2aedeec8546216b7eab082e43514f4c1cc0b71e743519101c372db458de47d3b
go-toolset-1.17-build-1.17.10-1.el7_9.ppc64le.rpm SHA-256: 5d0678ee6f13e427662b75e9f81ae7ed7a2dbbfbb777a1d54c12309c340b65b2
go-toolset-1.17-golang-1.17.10-1.el7_9.ppc64le.rpm SHA-256: df92d03e2c858295c528d045fb44c83dd698e5ee74fd4e0d907317f4f2e60461
go-toolset-1.17-golang-bin-1.17.10-1.el7_9.ppc64le.rpm SHA-256: 6c01172a89dd01d2aa4a37ebaf206b1a86e5b7c3efc091fe0efcaa9c19c9495e
go-toolset-1.17-golang-docs-1.17.10-1.el7_9.noarch.rpm SHA-256: b80f11db3439a3aa4252092fa45afda59257ba1de7bc11a6985b5b92ffe815f9
go-toolset-1.17-golang-misc-1.17.10-1.el7_9.ppc64le.rpm SHA-256: 88b2e0a0286770e7c776b456b8ecccc10fc4057d9208a92a87d8821f93dcedb2
go-toolset-1.17-golang-src-1.17.10-1.el7_9.ppc64le.rpm SHA-256: a87bcdfd17600d8a279b856b1269e157bf725ba49af636e219a177ca4f4bf484
go-toolset-1.17-golang-tests-1.17.10-1.el7_9.ppc64le.rpm SHA-256: 0717f24ac3ec46f13e6068714c52ccead40fbc7a81932d00c388ecf648d03ab5
go-toolset-1.17-runtime-1.17.10-1.el7_9.ppc64le.rpm SHA-256: 9cf1e9cad0876bde5fed03ecce215dd9ad6502fad5215ddeef63ec1098823e7a
go-toolset-1.17-scldevel-1.17.10-1.el7_9.ppc64le.rpm SHA-256: 982fb54aae6ad42eec44388c7208ae5e0ef2a91ccb518e7cdf496f04ae2eb4e0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility