Input validation error in Go programming language - CVE-2023-39321

 

Input validation error in Go programming language - CVE-2023-39321

Published: September 8, 2023


Vulnerability identifier: #VU80574
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-39321
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in crypto/tls when processing  post-handshake message on QUIC connections. A remote attacker can send an incomplete post-handshake message for a QUIC connection and perform a denial of service (DoS) attack.


Affected software

Go programming language
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Fedora
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Development Tools Module
openSUSE Leap
Run Once Duration Override Operator for Red Hat OpenShift
Service Interconnect
Consul
Cryostat
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift distributed tracing (RHOSDT)
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Cloud Pak for Data Scheduling
IBM Watson Discovery for IBM Cloud Pak for Data
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Multicluster Engine for Kubernetes
Juniper Secure Analytics (JSA)
Splunk Enterprise
IBM Qradar SIEM
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
ObjectScale
Planning Analytics Cartridge for Cloud Pak for Data
Storage Protect Server
IBM Sterling Order Management
Storage Protect Plus Container Agent
Storage Protect Plus Server
crun-wasm (Red Hat package)
toolbox-tests
toolbox
toolbox (Red Hat package)
udica
wasmedge (Red Hat package)
golang-github-prometheus-promu (Red Hat package)
coreos-installer (Red Hat package)
butane (Red Hat package)
containernetworking-plugins (Red Hat package)
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
google-benchmark (Red Hat package)
crun (Red Hat package)
aardvark-dns
netavark
skopeo (Red Hat package)
spdlog (Red Hat package)
gtest (Red Hat package)
fuse-overlayfs
crun
skopeo-tests
skopeo
golang
golang-bin
golang-shared
golang-docs
golang-misc
golang-src
golang-tests
dev-lang/go
go1.21
go1.21-doc
go1.21-race
go1.21-openssl
go1.21-openssl-race
go1.21-openssl-doc
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
buildah
buildah-tests
containers-common (Red Hat package)
containers-common
conmon (Red Hat package)
conmon
nmstate (Red Hat package)
haproxy (Red Hat package)
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
kata-containers (Red Hat package)
catch (Red Hat package)
criu-libs
criu-devel
criu
crit
python3-criu
libslirp-devel
libslirp
podman (Red Hat package)
python3-podman
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
podman-docker
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
rust-afterburn (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
fmt (Red Hat package)
ovn23.09 (Red Hat package)
cockpit-podman
Red Hat OpenShift GitOps
IBM Security Verify Access

How to mitigate CVE-2023-39321

Install updates from vendor's website.

Go programming language - addressed in versions 1.20.8, 1.21.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Service Interconnect - update to 1.5.3
Migration Toolkit for Containers - addressed in versions 1.7.14, 1.7.15, 1.8.3
Consul - addressed in versions 1.14.10, 1.15.6, 1.16.2
Multicluster Engine for Kubernetes - addressed in versions 2.1.9, 2.2.9, 2.3.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.8, 2.7.9, 2.8.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.22, 4.13.24, 4.14.0, 4.14.2, 4.14.4
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-14, 2023.2.1-3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14
crun-wasm (Red Hat package) - addressed in versions 0.0-3.rhaos4.14.el8, 1.8.5-3.rhaos4.14.el9
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - update to 0.1.2-1.rhaos4.14.el9
udica - update to 0.2.6-21
wasmedge (Red Hat package) - update to 0.12.1-2.rhaos4.14.el9
golang-github-prometheus-promu (Red Hat package) - update to 0.15.0-15.1.gitd5383c5.el8
coreos-installer (Red Hat package) - addressed in versions 0.17.0-1.rhaos4.14.el8, 0.17.0-1.rhaos4.14.el9
butane (Red Hat package) - update to 0.19.0-1.1.rhaos4.14.el8
containernetworking-plugins (Red Hat package) - update to 1.0.1-11.1.rhaos4.14.el8
runc (Red Hat package) - addressed in versions 1.1.9-2.el9_3, 1.1.9-2.1.rhaos4.14.el8, 1.1.9-2.1.rhaos4.14.el9
runc - update to 1.1.12-1.0.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.2.0
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
ObjectScale - update to 1.4.0
containernetworking-plugins - update to 1.4.0-2.0.1
google-benchmark (Red Hat package) - update to 1.8.2-1.el9
crun (Red Hat package) - addressed in versions 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
skopeo (Red Hat package) - addressed in versions 1.11.2-10.1.rhaos4.14.el8, 1.11.2-10.1.rhaos4.14.el9, 1.13.3-3.el9_3
spdlog (Red Hat package) - update to 1.12.0-1.rhaos4.14.el9
gtest (Red Hat package) - update to 1.13.0-1.el9
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
Red Hat OpenShift GitOps - update to 1.15.3
golang - addressed in versions 1.19.13-1.fc37, 1.20.8-1.fc38, 1.20.10-3.el7, 1.21.1-1.fc39
golang - update to 1.20.9-1
golang-bin - update to 1.20.9-1
golang-shared - update to 1.20.9-1
golang-docs - update to 1.20.9-1
golang-misc - update to 1.20.9-1
golang-src - update to 1.20.9-1
golang-tests - update to 1.20.9-1
dev-lang/go - update to 1.20.10
go1.21 - update to 1.21.1-150000.1.6.1
go1.21-doc - update to 1.21.1-150000.1.6.1
go1.21-race - update to 1.21.1-150000.1.6.1
go1.21-openssl - update to 1.21.4.1-150000.1.5.1
go1.21-openssl-race - update to 1.21.4.1-150000.1.5.1
go1.21-openssl-doc - update to 1.21.4.1-150000.1.5.1
cri-tools (Red Hat package) - addressed in versions 1.27.0-2.1.el8, 1.27.0-2.1.el9
cri-o (Red Hat package) - addressed in versions 1.27.1-8.1.rhaos4.14.git3fecb83.el8, 1.27.1-8.1.rhaos4.14.git3fecb83.el9, 1.27.1-13.1.rhaos4.14.git956c5f7.el8, 1.27.1-13.1.rhaos4.14.git956c5f7.el9
buildah (Red Hat package) - addressed in versions 1.29.1-10.1.rhaos4.14.el8, 1.29.1-10.1.rhaos4.14.el9, 1.31.3-2.el9_3
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common (Red Hat package) - update to 1-51.rhaos4.14.el8
containers-common - update to 1-81.0.1
conmon (Red Hat package) - addressed in versions 2.1.7-3.1.rhaos4.14.el8, 2.1.7-3.1.rhaos4.14.el9
conmon - update to 2.1.10-1
nmstate (Red Hat package) - update to 2.2.12-1.rhaos4.14.el8
haproxy (Red Hat package) - update to 2.6.13-1.rhaos4.14.el8
ignition (Red Hat package) - update to 2.16.2-1.1.rhaos4.14.el9
container-selinux (Red Hat package) - addressed in versions 2.221.0-1.rhaos4.14.el8, 2.221.0-2.rhaos4.14.el9, 2.223.0-1.rhaos4.14.el8, 2.223.0-2.rhaos4.14.el9
container-selinux - update to 2.229.0-2
kata-containers (Red Hat package) - update to 3.1.3-4.rhaos4.14.el9
catch (Red Hat package) - update to 3.3.2-1.el9
criu-libs - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-10.1.rhaos4.14.el8, 4.4.1-10.1.rhaos4.14.el9, 4.6.1-7.el9_3
Planning Analytics Cartridge for Cloud Pak for Data - update to 4.8.0
IBM Cloud Pak for Data Scheduling - update to 4.8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
python3-podman - update to 4.9.0-1
podman-tests - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
openshift-kuryr (Red Hat package) - update to 4.14.0-202309272140.p0.g8926a29.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - update to 4.14.0-202309272140.p0.gd2acdd5.assembly.stream.el8
openshift-ansible (Red Hat package) - addressed in versions 4.14.0-202310062327.p0.gf781421.assembly.stream.el8, 4.14.0-202310062327.p0.gf781421.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.14.0-202310191146.p0.g0c63f9d.assembly.stream.el8, 4.14.0-202310191146.p0.g0c63f9d.assembly.stream.el9, 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el8, 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.14.0-202310210404.p0.gf67aeb3.assembly.stream.el8, 4.14.0-202310210404.p0.gf67aeb3.assembly.stream.el9
rust-afterburn (Red Hat package) - update to 5.4.3-1.rhaos4.14.el9
kernel (Red Hat package) - addressed in versions 5.14.0-284.36.1.el9_2, 5.14.0-284.40.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.36.1.rt14.321.el9_2, 5.14.0-284.40.1.rt14.325.el9_2
Storage Protect Server - update to 8.1.23
fmt (Red Hat package) - update to 9.1.0-1.el9
IBM Security Verify Access - update to 10.0.9
IBM Sterling Order Management - update to 10.0.2403.1
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
ovn23.09 (Red Hat package) - update to 23.09.0-37.el9fdp
cockpit-podman - update to 84.1-1

External References

Related Security Bulletins