Skip to content

Conversation

@thaJeztah
Copy link
Member

Includes a security fix for crypto/elliptic (CVE-2023-24532).

go1.19.7 (released 2023-03-07) includes a security fix to the crypto/elliptic
package, as well as bug fixes to the linker, the runtime, and the crypto/x509
and syscall packages. See the Go 1.19.7 milestone on our issue tracker for
details.

https://go.dev/doc/devel/release#go1.19.minor

From the announcement:

We have just released Go versions 1.20.2 and 1.19.7, minor point releases.

These minor releases include 1 security fixes following the security policy:

  • crypto/elliptic: incorrect P-256 ScalarMult and ScalarBaseMult results
    >
    > The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an
    > incorrect result if called with some specific unreduced scalars (a scalar larger
    > than the order of the curve).
    >
    > This does not impact usages of crypto/ecdsa or crypto/ecdh.

This is CVE-2023-24532 and Go issue https://go.dev/issue/58647.

- What I did

- How I did it

- How to verify it

- Description for the changelog

- A picture of a cute animal (not mandatory but encouraged)

Includes a security fix for crypto/elliptic (CVE-2023-24532).

> go1.19.7 (released 2023-03-07) includes a security fix to the crypto/elliptic
> package, as well as bug fixes to the linker, the runtime, and the crypto/x509
> and syscall packages. See the Go 1.19.7 milestone on our issue tracker for
> details.

https://go.dev/doc/devel/release#go1.19.minor

From the announcement:

> We have just released Go versions 1.20.2 and 1.19.7, minor point releases.
>
> These minor releases include 1 security fixes following the security policy:
>
> - crypto/elliptic: incorrect P-256 ScalarMult and ScalarBaseMult results
    >
    >   The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an
    >   incorrect result if called with some specific unreduced scalars (a scalar larger
    >   than the order of the curve).
    >
    >   This does not impact usages of crypto/ecdsa or crypto/ecdh.
>
> This is CVE-2023-24532 and Go issue https://go.dev/issue/58647.

Signed-off-by: Sebastiaan van Stijn <[email protected]>
@thaJeztah
Copy link
Member Author

Hmm.. more flakiness on this test on Jenkins (arm64) (twice in a row, but different errors)

 === FAIL: libnetwork/networkdb TestNetworkDBCRUDTableEntries (7.63s)
     networkdb_test.go:310: Entry existence verification test failed for node2(43f0ed39215e)
 === FAIL: libnetwork/networkdb TestNetworkDBCRUDMediumCluster (22.07s)
     networkdb_test.go:426: timeout hit after 20s: node3:Waiting for cluster peers to be established

@thaJeztah
Copy link
Member Author

Oh! It's a different test! I mistook them for being the same 😂

@thaJeztah
Copy link
Member Author

All green now 👍

@thaJeztah thaJeztah merged commit 59e89b9 into moby:23.0 Mar 10, 2023
@thaJeztah thaJeztah deleted the 23.0_bump_go1.19.7 branch March 10, 2023 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants