Input validation error in Go programming language - CVE-2023-39323

 

Input validation error in Go programming language - CVE-2023-39323

Published: October 12, 2023


Vulnerability identifier: #VU81964
CSH Severity: Medium
CVSS v4 BT: 4.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-39323
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input when processing line directives (e.g. "//line") in the code. A remote attacker can bypass restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build".


Affected software

Go programming language
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
BIG-IP Next CNF
BIG-IP Next SPK
BIG-IP Next for Kubernetes
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
Fedora
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
AdGuard Home
Dell Data Lakehouse
Cloud Pak for Network Automation
ObjectScale
IBM Planning Analytics Workspace
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Protect Server
IBM supplied MQ Advanced container images
Storage Protect Plus Container Agent
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Splunk Enterprise
Operations Dashboard
IBM MQ Operator
IBM Spectrum Copy Data Management
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Automation Decision Services
Automation Assets in IBM Cloud Pak for Integration (CP4I)
golang-1.18 (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18-src (Ubuntu package)
golang
golang-devel
golang-help
golang-1.17 (Ubuntu package)
golang-1.17-src (Ubuntu package)
golang-1.17-go (Ubuntu package)
golang-1.20-src (Ubuntu package)
golang-1.20 (Ubuntu package)
golang-1.20-go (Ubuntu package)
golang-bin
golang-tests
golang-src
golang-misc
golang-docs
golang-shared
go1.20-race
go1.20-doc
go1.20
go1.20-debuginfo
dev-lang/go
go1.20-openssl-race
go1.20-openssl
go1.20-openssl-debuginfo
go1.20-openssl-doc
golang-1.21 (Ubuntu package)
golang-1.21-src (Ubuntu package)
golang-1.21-go (Ubuntu package)
go1.21-race
go1.21-doc
go1.21
go1.21-openssl-doc
go1.21-openssl-race
go1.21-openssl

How to mitigate CVE-2023-39323

Install updates from vendor's website.

Go programming language - addressed in versions 1.20.9, 1.21.2
AdGuard Home - addressed in versions 0.107.39, 0.108.0-b.47
Cloud Pak for Network Automation - update to 2.7.2
Splunk Enterprise - addressed in versions 9.0.8, 9.1.3, 9.1.6, 9.2.3, 9.3.1
Operations Dashboard - update to 2022.2.1-16
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
Dell Data Lakehouse - update to 1.4.0.0
ObjectScale - update to 1.4.0
golang - update to 1.15.7-36
golang-devel - update to 1.15.7-36
golang-help - update to 1.15.7-36
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.3
golang-1.20-src (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20 (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20-go (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-bin - update to 1.20.9-1
golang-tests - update to 1.20.9-1
golang-src - update to 1.20.9-1
golang-misc - update to 1.20.9-1
golang-docs - update to 1.20.9-1
golang-shared - update to 1.20.9-1
golang - update to 1.20.9-1
go1.20-race - update to 1.20.9-150000.1.26.1
go1.20-doc - update to 1.20.9-150000.1.26.1
go1.20 - update to 1.20.9-150000.1.26.1
go1.20-debuginfo - update to 1.20.9-150000.1.26.1
dev-lang/go - update to 1.20.10
golang - update to 1.20.10-1.48
golang - addressed in versions 1.20.10-2.fc38, 1.20.10-3.el7, 1.20.10-3.fc37, 1.21.3-1.fc39
go1.20-openssl-race - update to 1.20.11.1-150000.1.14.1
go1.20-openssl - update to 1.20.11.1-150000.1.14.1
go1.20-openssl-debuginfo - update to 1.20.11.1-150000.1.14.1
go1.20-openssl-doc - update to 1.20.11.1-150000.1.14.1
golang-1.21 (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-src (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-go (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
go1.21-race - update to 1.21.2-150000.1.9.1
go1.21-doc - update to 1.21.2-150000.1.9.1
go1.21 - update to 1.21.2-150000.1.9.1
go1.21-openssl-doc - update to 1.21.4.1-150000.1.5.1
go1.21-openssl-race - update to 1.21.4.1-150000.1.5.1
go1.21-openssl - update to 1.21.4.1-150000.1.5.1
IBM MQ Operator - addressed in versions 2.0.18, 2.4.7, 3.0.1
IBM Planning Analytics Workspace - update to 2.0.93
IBM Spectrum Copy Data Management - update to 2.2.22
IBM Cloud Pak for Watson AIOps - update to 4.4.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
Storage Protect Server - update to 8.1.23
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.15-r1, 9.3.3.3-r1, 9.3.4.1-r1
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.30, 23.0.2.2
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
IBM Automation Decision Services - update to 23.0.2.0.2
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-14, 2023.2.1-3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14

External References

Related Security Bulletins