Upstream information
Description
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey and ctx. That function uses named return parameters to free pkey and ctx if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey and ctx will be nil inside the deferred function that should free them.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having important severity.
No SUSE Bugzilla entries cross referenced. No SUSE Security Announcements cross referenced.List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Liberty Linux 8 |
| Patchnames: RHSA-2024:1472 RHSA-2024:1644 RHSA-2024:1646 RHSA-2024:3265 |
SUSE Liberty Linux 9 |
| Patchnames: RHSA-2024:1462 RHSA-2024:1501 RHSA-2024:1502 RHSA-2024:2562 RHSA-2024:2568 RHSA-2024:2569 |
SUSE Timeline for this CVE
CVE page created: Wed Mar 20 19:00:16 2024CVE page last modified: Sun Jun 16 11:53:37 2024