Bug 5746 - [Anolis OS 8] Bugfix for CVE-2022-30629
Summary: [Anolis OS 8] Bugfix for CVE-2022-30629
Status: NEW
Alias: None
Product: Anolis OS 8
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: 8.6
Hardware: All Linux
: P4-Low S4-trivial
Target Milestone: ---
Assignee: Jacob
QA Contact: shuming
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-07-06 13:01 UTC by 小龙
Modified: 2023-07-06 13:01 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-07-06 13:01:59 UTC
Description:
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

Broken commit info:

Bugfix commit info:
https://github.com/golang/go/commit/c15a8e2dbb5ac376a6ed890735341b812d6b965c
https://github.com/golang/go/commit/c838098c327a1b6d63446f4722e943b02d235d78 (go1.18.3)
https://github.com/golang/go/commit/fe4de36198794c447fbd9d7cc2d7199a506c76a5
https://github.com/golang/go/commit/c15a8e2dbb5ac376a6ed890735341b812d6b965c (go1.17.11)
https://github.com/golang/go/commit/c838098c327a1b6d63446f4722e943b02d235d78