Improper input validation in Go programming language - CVE-2018-16875
Published: December 14, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists on Go TLS servers accepting client certificates and TLS clients due to the crypto/x509 package does not limit the amount of work performed for each chain verification. A remote unauthenticated attacker can craft pathological inputs leading to a CPU denial of service.
Affected software
Arch Linux
Gentoo Linux
Amazon Linux AMI
Fedora
SUSE Linux Enterprise Module for Containers
Opensuse
SUSE Linux
openSUSE Leap
SUSE Package Hub for SUSE Linux Enterprise
runc
runc-debuginfo
containerd
golang
etcdctl
etcd
docker
docker-debuginfo
Storage Ceph
How to mitigate CVE-2018-16875
runc - update to 1.0.0~rc93-16.8.1
runc-debuginfo - update to 1.0.0~rc93-16.8.1
containerd - update to 1.4.4-16.38.1
golang - addressed in versions 1.10.7-1.fc28, 1.11.4-1.el6, 1.11.4-1.el7, 1.11.4-1.fc29, 1.11-6.fc29
etcdctl - update to 3.5.12-150000.7.6.1
etcd - update to 3.5.12-150000.7.6.1
Storage Ceph - update to 7.1
docker - update to 20.10.6_ce-98.66.1
docker-debuginfo - update to 20.10.6_ce-98.66.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Go
- Amazon Linux AMI update for golang
- Arch Linux update for go-pie
- Arch Linux update for go
- OpenSUSE Linux update for go1.11
- Gentoo update for Go
- OpenSUSE Linux update for go1.10
- OpenSUSE Linux update for containerd
- OpenSUSE Linux update for runc
- OpenSUSE Linux update for docker
- OpenSUSE Linux update for runc
- OpenSUSE Linux update for containerd
- OpenSUSE Linux update for containerd
- OpenSUSE Linux update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork
- OpenSUSE Linux update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork
- OpenSUSE Linux update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork
- OpenSUSE Linux update for helm
- SUSE update for containerd, docker, runc
- Multiple vulnerabilities in IBM Storage Ceph
- SUSE update for etcd
- Fedora 29 update for golang
- Fedora 28 update for golang
- Fedora EPEL 7 update for golang
- Fedora EPEL 6 update for golang
- Fedora 29 Containers update for golang