Merge version 1.15.15-1~deb11u2+rpi1 and 1.15.15-1~deb11u4 to produce 1.15.15-1~deb11... bullseye-staging archive/raspbian/1.15.15-1_deb11u4+rpi1 raspbian/1.15.15-1_deb11u4+rpi1
authorRaspbian automatic forward porter <root@raspbian.org>
Sun, 27 Mar 2022 06:37:31 +0000 (07:37 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Sun, 27 Mar 2022 06:37:31 +0000 (07:37 +0100)
1  2 
debian/changelog

index 4a3bcacc1b51c2341d3d711949f33ed8848a84fa,3f40e5c1ab041b7730b5f88924b54724a80e6b68..e415bb7ab6612e8f2381c1619b60bc40bf3e1227
@@@ -1,14 -1,20 +1,32 @@@
- golang-1.15 (1.15.15-1~deb11u2+rpi1) bullseye-staging; urgency=medium
++golang-1.15 (1.15.15-1~deb11u4+rpi1) bullseye-staging; urgency=medium
 +
 +  [changes brought forward from golang-1.10 1.10~rc2-1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Sat, 24 Feb 2018 12:22:04 +0000]
 +  * Build with GOARM=6
 +  * Disable testsuite.
 +  * Fix clean target.
 +
 +  [changes introduced in golang-1.12 1.12.7-3+rpi1 by Peter Michael Green]
 +  * Further clean target fixing.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Tue, 21 Dec 2021 18:45:03 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Sun, 27 Mar 2022 06:37:31 +0000
++
+ golang-1.15 (1.15.15-1~deb11u4) bullseye; urgency=medium
+   * Backport patch for CVE-2022-24921:
+     regexp: stack exhaustion compiling deeply nested expressions
+  -- Shengjing Zhu <zhsj@debian.org>  Fri, 04 Mar 2022 21:48:18 +0800
+ golang-1.15 (1.15.15-1~deb11u3) bullseye; urgency=medium
+   * Backport patches for CVE-2022-23806 CVE-2022-23772 CVE-2022-23773
+     + CVE-2022-23806: crypto/elliptic: fix IsOnCurve for big.Int values
+       that are not valid coordinates
+     + CVE-2022-23772: math/big: prevent large memory consumption in
+       Rat.SetString
+     + CVE-2022-23773: cmd/go: prevent branches from materializing into versions
+  -- Shengjing Zhu <zhsj@debian.org>  Fri, 11 Feb 2022 23:45:44 +0800
  
  golang-1.15 (1.15.15-1~deb11u2) bullseye; urgency=medium