Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security release for go 1.17.5 #11662

Closed
tgross opened this issue Dec 10, 2021 · 2 comments
Closed

security release for go 1.17.5 #11662

tgross opened this issue Dec 10, 2021 · 2 comments

Comments

@tgross
Copy link
Member

tgross commented Dec 10, 2021

Summary

Nomad 1.2.3 has been released to upgrade to Go 1.17.5. All prior versions of Nomad were built with a version of Go that contained 2 CVEs:

  • CVE-2021-44717 could allow a task on a Unix system with exhausted file handles to misdirect I/O.
  • CVE-2021-44716 could create unbounded memory growth in HTTP2 servers, but Nomad servers do not use HTTP2 and are unaffected.

Remediation

Users should upgrade Nomad agents to Nomad v1.2.3. Upgrading both servers and clients is recommended.

Backports

Nomad 1.1.9 and Nomad 1.0.15 have been released to upgrade the version of Go to 1.16.12 to remediate the vulnerabilities.

Links

@tgross tgross changed the title placeholder security release for go 1.17.5 Dec 13, 2021
@tgross
Copy link
Member Author

tgross commented Dec 13, 2021

Closed by #11665

@tgross tgross closed this as completed Dec 13, 2021
@github-actions
Copy link

I'm going to lock this issue because it has been closed for 120 days ⏳. This helps our maintainers find and focus on the active issues.
If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Oct 13, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant