Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3888


Security update for Golang Prometheus


Type: security
Severity: important
Issued: 2023-09-28
Description:
This update for Golang Prometheus fixes the following issues:

golang-github-prometheus-alertmanager:

- CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server
  while validating signatures for extremely large RSA keys. (bsc#1213880)
  There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

golang-github-prometheus-node_exporter:

- CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server
  while validating signatures for extremely large RSA keys. (bsc#1213880)
  There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.


              

Packages


  • golang-github-prometheus-alertmanager-0.23.0-150100.4.16.2