Skip to content

[release/1.5] update Go to 1.16.10#6210

Merged
estesp merged 2 commits intocontainerd:release/1.5from
thaJeztah:1.5_bump_go_1.16.10
Nov 9, 2021
Merged

[release/1.5] update Go to 1.16.10#6210
estesp merged 2 commits intocontainerd:release/1.5from
thaJeztah:1.5_bump_go_1.16.10

Conversation

@thaJeztah
Copy link
Copy Markdown
Member

[release/1.5] update Go to 1.16.10

go1.16.10 (released 2021-11-04) includes security fixes to the archive/zip and
debug/macho packages, as well as bug fixes to the compiler, linker, runtime, the
misc/wasm directory, and to the net/http package. See the Go 1.16.10 milestone
for details: https://github.com/golang/go/issues?q=milestone%3AGo1.16.10+label%3ACherryPickApproved

From the announcement e-mail:

[security] Go 1.17.3 and Go 1.16.10 are released

We have just released Go versions 1.17.3 and 1.16.10, minor point releases.
These minor releases include two security fixes following the security policy:

  • archive/zip: don't panic on (*Reader).Open
    Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made
    to panic by an attacker providing either a crafted ZIP archive containing
    completely invalid names or an empty filename argument.
    Thank you to Colin Arnott, SiteHost and Noah Santschi-Cooney, Sourcegraph Code
    Intelligence Team for reporting this issue. This is CVE-2021-41772 and Go issue
    golang.org/issue/48085.
  • debug/macho: invalid dynamic symbol table command can cause panic
    Malformed binaries parsed using Open or OpenFat can cause a panic when calling
    ImportedSymbols, due to an out-of-bounds slice operation.
    Thanks to Burak Çarıkçı - Yunus Yıldırım (CT-Zer0 Crypttech) for reporting this
    issue. This is CVE-2021-41771 and Go issue golang.org/issue/48990.

[release/1.5] update Go to 1.16.9

go1.16.9 (released 2021-10-07) includes a security fix to the linker and misc/wasm
directory, as well as bug fixes to the runtime and to the text/template package.
See the Go 1.16.9 milestone on our issue tracker for details:

go1.16.9 (released 2021-10-07) includes a security fix to the linker and misc/wasm
directory, as well as bug fixes to the runtime and to the text/template package.
See the Go 1.16.9 milestone on our issue tracker for details:

https://github.com/golang/go/issues?q=milestone%3AGo1.16.9+label%3ACherryPickApproved

Signed-off-by: Sebastiaan van Stijn <[email protected]>
go1.16.10 (released 2021-11-04) includes security fixes to the archive/zip and
debug/macho packages, as well as bug fixes to the compiler, linker, runtime, the
misc/wasm directory, and to the net/http package. See the Go 1.16.10 milestone
for details: https://github.com/golang/go/issues?q=milestone%3AGo1.16.10+label%3ACherryPickApproved

From the announcement e-mail:

[security] Go 1.17.3 and Go 1.16.10 are released

We have just released Go versions 1.17.3 and 1.16.10, minor point releases.
These minor releases include two security fixes following the security policy:

- archive/zip: don't panic on (*Reader).Open
  Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made
  to panic by an attacker providing either a crafted ZIP archive containing
  completely invalid names or an empty filename argument.
  Thank you to Colin Arnott, SiteHost and Noah Santschi-Cooney, Sourcegraph Code
  Intelligence Team for reporting this issue. This is CVE-2021-41772 and Go issue
  golang.org/issue/48085.
- debug/macho: invalid dynamic symbol table command can cause panic
  Malformed binaries parsed using Open or OpenFat can cause a panic when calling
  ImportedSymbols, due to an out-of-bounds slice operation.
  Thanks to Burak Çarıkçı - Yunus Yıldırım (CT-Zer0 Crypttech) for reporting this
  issue. This is CVE-2021-41771 and Go issue golang.org/issue/48990.

Signed-off-by: Sebastiaan van Stijn <[email protected]>
@thaJeztah
Copy link
Copy Markdown
Member Author

/retest-required

@theopenlab-ci
Copy link
Copy Markdown

theopenlab-ci Bot commented Nov 5, 2021

Build succeeded.

@estesp
Copy link
Copy Markdown
Member

estesp commented Nov 8, 2021

/test pull-containerd-node-e2e

Copy link
Copy Markdown
Member

@estesp estesp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@estesp estesp merged commit 7811ab3 into containerd:release/1.5 Nov 9, 2021
@thaJeztah thaJeztah deleted the 1.5_bump_go_1.16.10 branch November 9, 2021 21:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants