{"schema_version":"1.7.3","id":"SUSE-SU-2021:0937-1","published":"2021-03-24T11:22:26Z","modified":"2026-02-04T04:18:34.279907Z","related":["CVE-2021-27918","CVE-2021-27919"],"upstream":["CVE-2021-27918","CVE-2021-27919"],"summary":"Security update for go1.16","details":"This update for go1.16 fixes the following issues:\n\n- go1.16.2 (released 2021-03-11) (bsc#1182345) \n- go1.16.1 (released 2021-03-10) (bsc#1182345) \n  - CVE-2021-27918: Fixed an infinite loop when using xml.NewTokenDecoder with a custom TokenReader (bsc#1183333).\n  - CVE-2021-27919: Fixed an issue where archive/zip: can panic when calling Reader.Open (bsc#1183334).\n","affected":[{"package":{"name":"go1.16","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP2","purl":"pkg:rpm/suse/go1.16&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.16.2-1.8.1"}]}],"ecosystem_specific":{"binaries":[{"go1.16":"1.16.2-1.8.1","go1.16-doc":"1.16.2-1.8.1","go1.16-race":"1.16.2-1.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0937-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20210937-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182345"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183333"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-27918"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-27919"}]}