[20.10] Update Go to 1.16.10 go1.16.10 (released 2021-11-04) includes security fixes to the archive/zip and debug/macho packages, as well as bug fixes to the compiler, linker, runtime, the misc/wasm directory, and to the net/http package. See the Go 1.16.10 milestone for details: https://github.com/golang/go/issues?q=milestone%3AGo1.16.10+label%3ACherryPickApproved From the announcement e-mail: [security] Go 1.17.3 and Go 1.16.10 are released We have just released Go versions 1.17.3 and 1.16.10, minor point releases. These minor releases include two security fixes following the security policy: - archive/zip: don't panic on (*Reader).Open Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can be made to panic by an attacker providing either a crafted ZIP archive containing completely invalid names or an empty filename argument. Thank you to Colin Arnott, SiteHost and Noah Santschi-Cooney, Sourcegraph Code Intelligence Team for reporting this issue. This is CVE-2021-41772 and Go issue golang.org/issue/48085. - debug/macho: invalid dynamic symbol table command can cause panic Malformed binaries parsed using Open or OpenFat can cause a panic when calling ImportedSymbols, due to an out-of-bounds slice operation. Thanks to Burak Çarıkçı - Yunus Yıldırım (CT-Zer0 Crypttech) for reporting this issue. This is CVE-2021-41771 and Go issue golang.org/issue/48990. Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
diff --git a/Dockerfile b/Dockerfile index cff0abe..cf1200d 100644 --- a/Dockerfile +++ b/Dockerfile
@@ -3,7 +3,7 @@ ARG CROSS="false" ARG SYSTEMD="false" # IMPORTANT: When updating this please note that stdlib archive/tar pkg is vendored -ARG GO_VERSION=1.16.9 +ARG GO_VERSION=1.16.10 ARG DEBIAN_FRONTEND=noninteractive ARG VPNKIT_VERSION=0.5.0 ARG DOCKER_BUILDTAGS="apparmor seccomp"
diff --git a/Dockerfile.e2e b/Dockerfile.e2e index 1ba5016..41280ae 100644 --- a/Dockerfile.e2e +++ b/Dockerfile.e2e
@@ -1,4 +1,4 @@ -ARG GO_VERSION=1.16.9 +ARG GO_VERSION=1.16.10 FROM golang:${GO_VERSION}-alpine AS base ENV GO111MODULE=off
diff --git a/Dockerfile.simple b/Dockerfile.simple index 3783035..10f30be 100644 --- a/Dockerfile.simple +++ b/Dockerfile.simple
@@ -5,7 +5,7 @@ # This represents the bare minimum required to build and test Docker. -ARG GO_VERSION=1.16.9 +ARG GO_VERSION=1.16.10 FROM golang:${GO_VERSION}-buster ENV GO111MODULE=off
diff --git a/Dockerfile.windows b/Dockerfile.windows index 870be1b..37b9198 100644 --- a/Dockerfile.windows +++ b/Dockerfile.windows
@@ -165,7 +165,7 @@ # Use PowerShell as the default shell SHELL ["powershell", "-Command", "$ErrorActionPreference = 'Stop'; $ProgressPreference = 'SilentlyContinue';"] -ARG GO_VERSION=1.16.9 +ARG GO_VERSION=1.16.10 ARG GOTESTSUM_COMMIT=v0.5.3 # Environment variable notes: