ã¯ã˜ã‚㫠先日ãªã‚“ã¨ãªã—ã« go.1.19 release note よんã§ãŸã‚‰ã€crypto/randã®é …ç›®ã§èˆˆå‘³æ·±ã„一文を見ã¤ã‘㟠Read no longer buffers random data obtained from the operating system between calls. 当時ã®åƒ•ã‚‚æ°—ã«ãªã£ã¦ã„ãŸã‚ˆã† ã–ã£ã¨è¦‹ãŸã‘ã© crypto/rand.Read()ã§å†…部ãƒãƒƒãƒ•ã‚¡å–らãªããªã£ãŸã‚Š net パッケージ㌠context.DealineExceededã¨ã‹ context.Canceled を満ãŸã™å½¢ã§ã‚¨ãƒ©ãƒ¼è¿”ã™ã‚ˆã†ã«ãªã£ãŸã‚ŠãŒã»ãˆã€œãƒã‚¤ãƒ³ãƒˆã ã£ãŸã€‚ã‚ã¨ã¯ fmt.Append よã•ãã†ã£ã™ãhttps://t.co/8cfrZ7dBZR— convto (@convto) 2022å¹´6月11æ—¥ ã‚‚ã¨ã‚‚㨠CVE-2021-3538 ã‚’ã¡ã‚ƒã‚“ã¨èªã‚€ - ã¡ã‚Š
{{#tags}}- {{label}}
{{/tags}}