UbuntuUpdates.org

Package "golang-golang-x-net-dev"

Name: golang-golang-x-net-dev

Description:

Supplementary Go networking libraries

Latest version: 1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1
Release: jammy (22.04)
Level: security
Repository: universe
Head package: golang-golang-x-net
Homepage: https://godoc.org/golang.org/x/net

Links


Download "golang-golang-x-net-dev"


Other versions of "golang-golang-x-net-dev" in Jammy

Repository Area Version
base universe 1:0.0+git20211209.491a49a+dfsg-1

Changelog

Version: 1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1 2026-10-08 03:07:28 UTC

golang-golang-x-net (1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of Service in startGracefulShutdownInternal
    - debian/patches/CVE-2022-27664.patch: http2: handle server errors after
      sending GOAWAY in http2/server.go, http2/server_test.go.
    - CVE-2022-27664
  * SECURITY UPDATE: Denial of service in HPACK decoding.
    - debian/patches/CVE-2022-41723.patch: http2/hpack: avoid quadratic
      complexity in hpack decoding in http2/hpack/hpack.go,
      http2/hpack/hpack_test.go.
    - CVE-2022-41723
  * SECURITY UPDATE: XSS Attack in text rendering
    - debian/patches/CVE-2023-3978.patch: html: only render content literally in
      the HTML namespace in html/render.go, html/render_test.go.
    - CVE-2023-3978
  * SECURITY UPDATE: Denial of service in parse function.
    - debian/patches/CVE-2024-45338.patch: html: use strings.EqualFold instead
      of lowering ourselves Instead of using strings.ToLower and == to check
      case insensitive equality, just use strings.EqualFold, even when the
      strings are only ASCII. This prevents us unnecessarily lowering extremely
      long strings, which can be a somewhat expensive operation, even if we're
      only attempting to compare equality with five characters. Thanks to Guido
      Vranken for reporting this issue. Fixes golang/go#70906 Fixes
      CVE-2024-45338 Change-Id: I323b919f912d60dab6a87cadfdcac3e6b54cd128
      Reviewed-on: https://go-review.googlesource.com/c/net/+/637536 LUCI-
      TryBot-Result: Go LUCI Auto-Submit: Gopher Robot
       Reviewed-by: Roland Shoemaker
      Reviewed-by: Tatiana Bradley in
      html/doctype.go, html/foreign.go, html/parse.go.
    - CVE-2024-45338
  * SECURITY UPDATE: Erroneous interpretation of tags in readStartTag
    - debian/patches/CVE-2025-22872.patch: html: properly handle trailing
      solidus in unquoted attribute value in foreign content in html/token.go,
      html/token_test.go.
    - CVE-2025-22872
  * SECURITY UPDATE: Denial of service in HTML Parsing
    - debian/patches/CVE-2025-47911.patch: html: impose open element stack size
      limit in html/escape.go, html/parse.go, html/parse_test.go.
    - CVE-2025-47911
  * SECURITY UPDATE: Denial of service in HTML Parsing
    - debian/patches/CVE-2025-58190.patch: html: align in row insertion mode
      with spec in html/parse.go, html/parse_test.go.
    - CVE-2025-58190
  * SECURITY UPDATE: ACL Bypass in idna
    - debian/patches/CVE-2026-39821.patch: [internal-branch.go1.26-vendor] idna:
      reject all-ASCII xn-- labels on all Go versions in idna/idna10.0.0.go,
      idna/idna9.0.0.go, idna/idna_test.go.
    - CVE-2026-39821

 -- John Breton Mon, 05 Oct 2026 09:42:47 -0400

CVE-2022-27664 In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closin
CVE-2022-41723 A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small
CVE-2023-3978 Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS at
CVE-2024-45338 An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow pa
CVE-2025-22872 The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using T
CVE-2025-47911 The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service
CVE-2025-58190 The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (Do
CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl



About   -   Send Feedback to @ubuntu_updates