Red Hat Product Errata RHSA-2026:19139 - Security Advisory Issued: 2026-05-19 Updated: 2026-05-19 RHSA-2026:19139 - Security Advisory Overview Updated Packages Synopsis Important: go-fdo-client security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for go-fdo-client is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description go-fdo-client is the device-side implementation of FIDO Device Onboard specification in Go. It provides an FDO client that interacts with FDO manufacturer and owner servers to perform device on-boarding. Security Fix(es): crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Fixes BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVEs CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM go-fdo-client-1.0.0-3.el10_2.src.rpm SHA-256: 355432ecf8851a66eb50138251eb3d88e693401f587ed86bd68e0bb7d5ed06a4 x86_64 go-fdo-client-1.0.0-3.el10_2.x86_64.rpm SHA-256: fc7fb8a6221a66ed7e97e7a6b89a8f3d9604ae4ad17399d50d8e43e488c6eecd go-fdo-client-debuginfo-1.0.0-3.el10_2.x86_64.rpm SHA-256: 35a44e0b404436a1d8c703b104ccfec2d1e4c472eaac11fdbed284fbd4f47aae go-fdo-client-debugsource-1.0.0-3.el10_2.x86_64.rpm SHA-256: b5fa0f39b9611d1c114bcbab053e88fc22d8f67dc3c6f69a6b30e51392991b58 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM go-fdo-client-1.0.0-3.el10_2.src.rpm SHA-256: 355432ecf8851a66eb50138251eb3d88e693401f587ed86bd68e0bb7d5ed06a4 x86_64 go-fdo-client-1.0.0-3.el10_2.x86_64.rpm SHA-256: fc7fb8a6221a66ed7e97e7a6b89a8f3d9604ae4ad17399d50d8e43e488c6eecd go-fdo-client-debuginfo-1.0.0-3.el10_2.x86_64.rpm SHA-256: 35a44e0b404436a1d8c703b104ccfec2d1e4c472eaac11fdbed284fbd4f47aae go-fdo-client-debugsource-1.0.0-3.el10_2.x86_64.rpm SHA-256: b5fa0f39b9611d1c114bcbab053e88fc22d8f67dc3c6f69a6b30e51392991b58 Red Hat Enterprise Linux for ARM 64 10 SRPM go-fdo-client-1.0.0-3.el10_2.src.rpm SHA-256: 355432ecf8851a66eb50138251eb3d88e693401f587ed86bd68e0bb7d5ed06a4 aarch64 go-fdo-client-1.0.0-3.el10_2.aarch64.rpm SHA-256: 5682b3c76a5da15dc29ee55c290ff85ac8ec0ae1820bd26e943d856e71d4c7c8 go-fdo-client-debuginfo-1.0.0-3.el10_2.aarch64.rpm SHA-256: 256188b34f8c02a459c7db53eafbb52dfa40a1ca3abe4fe391e7ed5cb7e470d6 go-fdo-client-debugsource-1.0.0-3.el10_2.aarch64.rpm SHA-256: 4028d5e248a4c94fb9b50a092fc474e776e30329ca91cbfabe5cb5ddd4721149 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM go-fdo-client-1.0.0-3.el10_2.src.rpm SHA-256: 355432ecf8851a66eb50138251eb3d88e693401f587ed86bd68e0bb7d5ed06a4 aarch64 go-fdo-client-1.0.0-3.el10_2.aarch64.rpm SHA-256: 5682b3c76a5da15dc29ee55c290ff85ac8ec0ae1820bd26e943d856e71d4c7c8 go-fdo-client-debuginfo-1.0.0-3.el10_2.aarch64.rpm SHA-256: 256188b34f8c02a459c7db53eafbb52dfa40a1ca3abe4fe391e7ed5cb7e470d6 go-fdo-client-debugsource-1.0.0-3.el10_2.aarch64.rpm SHA-256: 4028d5e248a4c94fb9b50a092fc474e776e30329ca91cbfabe5cb5ddd4721149 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 SRPM go-fdo-client-1.0.0-3.el10_2.src.rpm SHA-256: 355432ecf8851a66eb50138251eb3d88e693401f587ed86bd68e0bb7d5ed06a4 aarch64 go-fdo-client-1.0.0-3.el10_2.aarch64.rpm SHA-256: 5682b3c76a5da15dc29ee55c290ff85ac8ec0ae1820bd26e943d856e71d4c7c8 go-fdo-client-debuginfo-1.0.0-3.el10_2.aarch64.rpm SHA-256: 256188b34f8c02a459c7db53eafbb52dfa40a1ca3abe4fe391e7ed5cb7e470d6 go-fdo-client-debugsource-1.0.0-3.el10_2.aarch64.rpm SHA-256: 4028d5e248a4c94fb9b50a092fc474e776e30329ca91cbfabe5cb5ddd4721149 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 SRPM go-fdo-client-1.0.0-3.el10_2.src.rpm SHA-256: 355432ecf8851a66eb50138251eb3d88e693401f587ed86bd68e0bb7d5ed06a4 x86_64 go-fdo-client-1.0.0-3.el10_2.x86_64.rpm SHA-256: fc7fb8a6221a66ed7e97e7a6b89a8f3d9604ae4ad17399d50d8e43e488c6eecd go-fdo-client-debuginfo-1.0.0-3.el10_2.x86_64.rpm SHA-256: 35a44e0b404436a1d8c703b104ccfec2d1e4c472eaac11fdbed284fbd4f47aae go-fdo-client-debugsource-1.0.0-3.el10_2.x86_64.rpm SHA-256: b5fa0f39b9611d1c114bcbab053e88fc22d8f67dc3c6f69a6b30e51392991b58 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 SRPM go-fdo-client-1.0.0-3.el10_2.src.rpm SHA-256: 355432ecf8851a66eb50138251eb3d88e693401f587ed86bd68e0bb7d5ed06a4 x86_64 go-fdo-client-1.0.0-3.el10_2.x86_64.rpm SHA-256: fc7fb8a6221a66ed7e97e7a6b89a8f3d9604ae4ad17399d50d8e43e488c6eecd go-fdo-client-debuginfo-1.0.0-3.el10_2.x86_64.rpm SHA-256: 35a44e0b404436a1d8c703b104ccfec2d1e4c472eaac11fdbed284fbd4f47aae go-fdo-client-debugsource-1.0.0-3.el10_2.x86_64.rpm SHA-256: b5fa0f39b9611d1c114bcbab053e88fc22d8f67dc3c6f69a6b30e51392991b58 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 SRPM go-fdo-client-1.0.0-3.el10_2.src.rpm SHA-256: 355432ecf8851a66eb50138251eb3d88e693401f587ed86bd68e0bb7d5ed06a4 aarch64 go-fdo-client-1.0.0-3.el10_2.aarch64.rpm SHA-256: 5682b3c76a5da15dc29ee55c290ff85ac8ec0ae1820bd26e943d856e71d4c7c8 go-fdo-client-debuginfo-1.0.0-3.el10_2.aarch64.rpm SHA-256: 256188b34f8c02a459c7db53eafbb52dfa40a1ca3abe4fe391e7ed5cb7e470d6 go-fdo-client-debugsource-1.0.0-3.el10_2.aarch64.rpm SHA-256: 4028d5e248a4c94fb9b50a092fc474e776e30329ca91cbfabe5cb5ddd4721149 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A Denial of Service vulnerability (CVE-2026-32283, CVSS 7.5 HIGH) exists in the Go `crypto/tls` library where an attacker can crash a service by sending multiple TLS 1.3 key update messages. The vulnerability affects Go versions earlier than 1.25.9 and versions 1.26.0 through 1.26.1, requiring an upgrade to Go 1.25.9 or 1.26.2 to remediate. This impacts the `go-fdo-client` package on Red Hat Enterprise Linux 10, which relies on the affected Go library.