Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:23103: Important: delve security update

This security update addresses three high-severity Denial of Service vulnerabilities (CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, each CVSS 7.5) in the Go programming language's `crypto/x509` and `crypto/tls` packages, which are used by the Delve debugger, involving inefficient certificate chain validation and handling of TLS 1.3 key update messages. The affected Go versions are `go < 1.25.9` and `go >= 1.26.0, < 1.26.2`. The fixed versions are Go `1.25.9` or `1.26.2`, and the Red Hat advisory provides updated Delve packages for Red Hat Enterprise Linux 10.0 Extended Update Support.
Read Full Article →

Red Hat Product Errata RHSA-2026:23103 - Security Advisory Issued: 2026-06-04 Updated: 2026-06-04 RHSA-2026:23103 - Security Advisory Overview Updated Packages Synopsis Important: delve security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for delve is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible. Security Fix(es): crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVEs CVE-2026-32280 CVE-2026-32281 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM delve-1.25.2-4.el10_0.src.rpm SHA-256: f15e581929ed47d929a03c6945509a8c46307b77291d3d085ecf274ce22b46ca x86_64 delve-1.25.2-4.el10_0.x86_64.rpm SHA-256: 150bf6f4e3c07b3ed07095f4a045ffd89dea2d282280652d4e0236d65d78d9b9 delve-debuginfo-1.25.2-4.el10_0.x86_64.rpm SHA-256: f351467f735148da5de3076a5fceec418393a4edc8e119e8eee6b92ad0e47111 delve-debugsource-1.25.2-4.el10_0.x86_64.rpm SHA-256: a5977b3debc160e94635f3863e61b2e64bd538a2d3df59a8682cff59d0de5523 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM delve-1.25.2-4.el10_0.src.rpm SHA-256: f15e581929ed47d929a03c6945509a8c46307b77291d3d085ecf274ce22b46ca ppc64le delve-1.25.2-4.el10_0.ppc64le.rpm SHA-256: b978052f1b0dbc591c5be798b52b91874771c14e983386ca1203acc273e9aaee delve-debuginfo-1.25.2-4.el10_0.ppc64le.rpm SHA-256: 15e514ba56739e24bac4ad8f091f698a72ef7aceba1a1223775072163ed29b0e delve-debugsource-1.25.2-4.el10_0.ppc64le.rpm SHA-256: 110ec66fbe627f4bfe69ea2a442c07eb555a13257bb65a06f7566619b7401259 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM delve-1.25.2-4.el10_0.src.rpm SHA-256: f15e581929ed47d929a03c6945509a8c46307b77291d3d085ecf274ce22b46ca aarch64 delve-1.25.2-4.el10_0.aarch64.rpm SHA-256: 9d337b29616ad9e7f71854140c443a83a792e487415f9cd04cc4ce6628f4948a delve-debuginfo-1.25.2-4.el10_0.aarch64.rpm SHA-256: cc0f6c39d8d7429202baa1aead972698d3d45d207bdc7aa609513a0829354fd1 delve-debugsource-1.25.2-4.el10_0.aarch64.rpm SHA-256: e2f1afaa9c8c9575ea29c597b966b3a575fd776710e3678d17b4ade9ca07bf5c Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM delve-1.25.2-4.el10_0.src.rpm SHA-256: f15e581929ed47d929a03c6945509a8c46307b77291d3d085ecf274ce22b46ca aarch64 delve-1.25.2-4.el10_0.aarch64.rpm SHA-256: 9d337b29616ad9e7f71854140c443a83a792e487415f9cd04cc4ce6628f4948a delve-debuginfo-1.25.2-4.el10_0.aarch64.rpm SHA-256: cc0f6c39d8d7429202baa1aead972698d3d45d207bdc7aa609513a0829354fd1 delve-debugsource-1.25.2-4.el10_0.aarch64.rpm SHA-256: e2f1afaa9c8c9575ea29c597b966b3a575fd776710e3678d17b4ade9ca07bf5c Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 SRPM delve-1.25.2-4.el10_0.src.rpm SHA-256: f15e581929ed47d929a03c6945509a8c46307b77291d3d085ecf274ce22b46ca ppc64le delve-1.25.2-4.el10_0.ppc64le.rpm SHA-256: b978052f1b0dbc591c5be798b52b91874771c14e983386ca1203acc273e9aaee delve-debuginfo-1.25.2-4.el10_0.ppc64le.rpm SHA-256: 15e514ba56739e24bac4ad8f091f698a72ef7aceba1a1223775072163ed29b0e delve-debugsource-1.25.2-4.el10_0.ppc64le.rpm SHA-256: 110ec66fbe627f4bfe69ea2a442c07eb555a13257bb65a06f7566619b7401259 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 SRPM delve-1.25.2-4.el10_0.src.rpm SHA-256: f15e581929ed47d929a03c6945509a8c46307b77291d3d085ecf274ce22b46ca x86_64 delve-1.25.2-4.el10_0.x86_64.rpm SHA-256: 150bf6f4e3c07b3ed07095f4a045ffd89dea2d282280652d4e0236d65d78d9b9 delve-debuginfo-1.25.2-4.el10_0.x86_64.rpm SHA-256: f351467f735148da5de3076a5fceec418393a4edc8e119e8eee6b92ad0e47111 delve-debugsource-1.25.2-4.el10_0.x86_64.rpm SHA-256: a5977b3debc160e94635f3863e61b2e64bd538a2d3df59a8682cff59d0de5523 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article