QID 355111

Date Published: 2023-05-29

QID 355111: Amazon Linux Security Advisory for golist : ALAS2023-2023-046

2023-05-11:( CVE-2022-1996 has changed status to not affected for this package and has been removed from this advisory. a flaw was found in golang.
The http/1 client accepted invalid transfer-encoding headers indicating "chunked" encoding.
This issue could allow request smuggling, but only if combined with an intermediate server that also improperly accepts the header as invalid. (
( CVE-2022-1705) a flaw was found in the golang standard library, go/parser.
When calling any parse functions on the go source code, which contains deeply nested types or declarations, a panic can occur due to stack exhaustion.
This issue allows an attacker to impact system availability. (
( CVE-2022-1962) a buffer overflow flaw was found in golangs library encoding/pem.
This flaw allows an attacker to use a large pem input (more than 5 mb) ), causing a stack overflow in decode, which leads to a loss of availability. (
( CVE-2022-24675) a broken cryptographic algorithm flaw was found in golang.org/x/crypto/ssh.
This issue causes a client to fail authentification with rsa keys to servers that reject signature algorithms based on sha-2, enabling an attacker to crash the server, resulting in a loss of availability. (
( CVE-2022-27191) a flaw was found in golang encoding/xml.
When calling decoder.
Skip while parsing a deeply nested xml document, a panic can occur due to stack exhaustion and allows an attacker to impact system availability. (

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2023-2023-046 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2023-2023-046 amazon linux 2023 URL Logo alas.aws.amazon.com/AL2023/ALAS-2023-046.html