|
golang-golang-x-net (1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1) jammy-security; urgency=medium
* SECURITY UPDATE: Denial of Service in startGracefulShutdownInternal
- debian/patches/CVE-2022-27664.patch: http2: handle server errors after
sending GOAWAY in http2/server.go, http2/server_test.go.
- CVE-2022-27664
* SECURITY UPDATE: Denial of service in HPACK decoding.
- debian/patches/CVE-2022-41723.patch: http2/hpack: avoid quadratic
complexity in hpack decoding in http2/hpack/hpack.go,
http2/hpack/hpack_test.go.
- CVE-2022-41723
* SECURITY UPDATE: XSS Attack in text rendering
- debian/patches/CVE-2023-3978.patch: html: only render content literally in
the HTML namespace in html/render.go, html/render_test.go.
- CVE-2023-3978
* SECURITY UPDATE: Denial of service in parse function.
- debian/patches/CVE-2024-45338.patch: html: use strings.EqualFold instead
of lowering ourselves Instead of using strings.ToLower and == to check
case insensitive equality, just use strings.EqualFold, even when the
strings are only ASCII. This prevents us unnecessarily lowering extremely
long strings, which can be a somewhat expensive operation, even if we're
only attempting to compare equality with five characters. Thanks to Guido
Vranken for reporting this issue. Fixes golang/go#70906 Fixes
CVE-2024-45338 Change-Id: I323b919f912d60dab6a87cadfdcac3e6b54cd128
Reviewed-on: https://go-review.googlesource.com/c/net/+/637536 LUCI-
TryBot-Result: Go LUCI Auto-Submit: Gopher Robot
Reviewed-by: Roland Shoemaker
Reviewed-by: Tatiana Bradley in
html/doctype.go, html/foreign.go, html/parse.go.
- CVE-2024-45338
* SECURITY UPDATE: Erroneous interpretation of tags in readStartTag
- debian/patches/CVE-2025-22872.patch: html: properly handle trailing
solidus in unquoted attribute value in foreign content in html/token.go,
html/token_test.go.
- CVE-2025-22872
* SECURITY UPDATE: Denial of service in HTML Parsing
- debian/patches/CVE-2025-47911.patch: html: impose open element stack size
limit in html/escape.go, html/parse.go, html/parse_test.go.
- CVE-2025-47911
* SECURITY UPDATE: Denial of service in HTML Parsing
- debian/patches/CVE-2025-58190.patch: html: align in row insertion mode
with spec in html/parse.go, html/parse_test.go.
- CVE-2025-58190
* SECURITY UPDATE: ACL Bypass in idna
- debian/patches/CVE-2026-39821.patch: [internal-branch.go1.26-vendor] idna:
reject all-ASCII xn-- labels on all Go versions in idna/idna10.0.0.go,
idna/idna9.0.0.go, idna/idna_test.go.
- CVE-2026-39821
-- John Breton Mon, 05 Oct 2026 09:42:47 -0400
|
| CVE-2022-27664 |
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closin |
| CVE-2022-41723 |
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small |
| CVE-2023-3978 |
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS at |
| CVE-2024-45338 |
An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow pa |
| CVE-2025-22872 |
The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using T |
| CVE-2025-47911 |
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service |
| CVE-2025-58190 |
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (Do |
| CVE-2026-39821 |
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl |
|