Input validation error in Go programming language - CVE-2023-39323
Published: October 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input when processing line directives (e.g. "//line") in the code. A remote attacker can bypass restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build".
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
BIG-IP Next CNF
BIG-IP Next SPK
BIG-IP Next for Kubernetes
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
Fedora
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
AdGuard Home
Dell Data Lakehouse
Cloud Pak for Network Automation
ObjectScale
IBM Planning Analytics Workspace
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Protect Server
IBM supplied MQ Advanced container images
Storage Protect Plus Container Agent
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Splunk Enterprise
Operations Dashboard
IBM MQ Operator
IBM Spectrum Copy Data Management
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Automation Decision Services
Automation Assets in IBM Cloud Pak for Integration (CP4I)
golang-1.18 (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18-src (Ubuntu package)
golang
golang-devel
golang-help
golang-1.17 (Ubuntu package)
golang-1.17-src (Ubuntu package)
golang-1.17-go (Ubuntu package)
golang-1.20-src (Ubuntu package)
golang-1.20 (Ubuntu package)
golang-1.20-go (Ubuntu package)
golang-bin
golang-tests
golang-src
golang-misc
golang-docs
golang-shared
go1.20-race
go1.20-doc
go1.20
go1.20-debuginfo
dev-lang/go
go1.20-openssl-race
go1.20-openssl
go1.20-openssl-debuginfo
go1.20-openssl-doc
golang-1.21 (Ubuntu package)
golang-1.21-src (Ubuntu package)
golang-1.21-go (Ubuntu package)
go1.21-race
go1.21-doc
go1.21
go1.21-openssl-doc
go1.21-openssl-race
go1.21-openssl
How to mitigate CVE-2023-39323
AdGuard Home - addressed in versions 0.107.39, 0.108.0-b.47
Cloud Pak for Network Automation - update to 2.7.2
Splunk Enterprise - addressed in versions 9.0.8, 9.1.3, 9.1.6, 9.2.3, 9.3.1
Operations Dashboard - update to 2022.2.1-16
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
Dell Data Lakehouse - update to 1.4.0.0
ObjectScale - update to 1.4.0
golang - update to 1.15.7-36
golang-devel - update to 1.15.7-36
golang-help - update to 1.15.7-36
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.20-src (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20 (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20-go (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-bin - update to 1.20.9-1
golang-tests - update to 1.20.9-1
golang-src - update to 1.20.9-1
golang-misc - update to 1.20.9-1
golang-docs - update to 1.20.9-1
golang-shared - update to 1.20.9-1
golang - update to 1.20.9-1
go1.20-race - update to 1.20.9-150000.1.26.1
go1.20-doc - update to 1.20.9-150000.1.26.1
go1.20 - update to 1.20.9-150000.1.26.1
go1.20-debuginfo - update to 1.20.9-150000.1.26.1
dev-lang/go - update to 1.20.10
golang - update to 1.20.10-1.48
golang - addressed in versions 1.20.10-2.fc38, 1.20.10-3.el7, 1.20.10-3.fc37, 1.21.3-1.fc39
go1.20-openssl-race - update to 1.20.11.1-150000.1.14.1
go1.20-openssl - update to 1.20.11.1-150000.1.14.1
go1.20-openssl-debuginfo - update to 1.20.11.1-150000.1.14.1
go1.20-openssl-doc - update to 1.20.11.1-150000.1.14.1
golang-1.21 (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-src (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-go (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
go1.21-race - update to 1.21.2-150000.1.9.1
go1.21-doc - update to 1.21.2-150000.1.9.1
go1.21 - update to 1.21.2-150000.1.9.1
go1.21-openssl-doc - update to 1.21.4.1-150000.1.5.1
go1.21-openssl-race - update to 1.21.4.1-150000.1.5.1
go1.21-openssl - update to 1.21.4.1-150000.1.5.1
IBM MQ Operator - addressed in versions 2.0.18, 2.4.7, 3.0.1
IBM Planning Analytics Workspace - update to 2.0.93
IBM Spectrum Copy Data Management - update to 2.2.22
IBM Cloud Pak for Watson AIOps - update to 4.4.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
Storage Protect Server - update to 8.1.23
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.15-r1, 9.3.3.3-r1, 9.3.4.1-r1
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.30, 23.0.2.2
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
IBM Automation Decision Services - update to 23.0.2.0.2
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-14, 2023.2.1-3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14
External References
Related Security Bulletins
- Improper input validation in Go programming language
- SUSE update for go1.20
- SUSE update for go1.21
- AdGuardHome update for Go programming language
- Amazon Linux AMI update for golang
- Fedora 37 update for golang
- Fedora 39 update for golang
- Fedora 38 update for golang
- SUSE update for go1.20-openssl
- SUSE update for go1.21-openssl
- Fedora EPEL 7 update for golang
- Gentoo update for Go
- Platform Navigator and Automation Assets in IBM Cloud Pak for Integration update for Go
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Ubuntu update for golang-1.20
- Multiple vulnerabilities in IBM Operations Dashboard
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Automation Decision Services
- openEuler update for golang
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Storage Protect Plus Container Agent
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Robotic Process Automation
- Multiple vulnerabilities in Storage Protect Plus Server
- Splunk Enterprise update for third-party components
- Ubuntu update for golang-1.17
- Ubuntu update for golang-1.18
- Amazon Linux AMI update for golang
- Amazon Linux AMI update for ecs-service-connect-agent
- Anolis OS update for golang
- Dell Data Lakehouse update for third-party components
- Improper input validation in Go used by fsm and cert-manager in BIG-IP Next SPK/CNF
- Improper input validation in Go used by fsm and cert-manager in BIG-IP Next for Kubernetes