Red Hat Product Errata RHSA-2026:35832 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35832 - Security Advisory Overview Updated Packages Synopsis Important: golang-github-openprinting-ipp-usb security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for golang-github-openprinting-ipp-usb is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables driverless support for USB devices capable of using IPP-over-USB protocol. Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVEs CVE-2026-27145 CVE-2026-33811 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 x86_64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.x86_64.rpm SHA-256: d3b734cbdbf6ebe95abfc0a9853a43fef3036ab4de739ad5b278eb3f56351a55 ipp-usb-0.9.27-7.el10_2.2.x86_64.rpm SHA-256: 44cf35e13603e040c10d974a408b7df83ce6e4418f4f216dbd3c6ddec5c38e25 ipp-usb-debuginfo-0.9.27-7.el10_2.2.x86_64.rpm SHA-256: 44f8e6e4d9b61c23f4af476e6be507a59381c692e84ed89f60c312b576fd7c31 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 x86_64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.x86_64.rpm SHA-256: d3b734cbdbf6ebe95abfc0a9853a43fef3036ab4de739ad5b278eb3f56351a55 ipp-usb-0.9.27-7.el10_2.2.x86_64.rpm SHA-256: 44cf35e13603e040c10d974a408b7df83ce6e4418f4f216dbd3c6ddec5c38e25 ipp-usb-debuginfo-0.9.27-7.el10_2.2.x86_64.rpm SHA-256: 44f8e6e4d9b61c23f4af476e6be507a59381c692e84ed89f60c312b576fd7c31 Red Hat Enterprise Linux for IBM z Systems 10 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 s390x golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.s390x.rpm SHA-256: 8f6e8b9e67e323be814c50d9d0df230750cac79b359845b835cf1456cd8c6faa ipp-usb-0.9.27-7.el10_2.2.s390x.rpm SHA-256: e17f362b3e90086c01bd09905a847c2b3ae81e745f6a825e3ece05b6f8ba6e9a ipp-usb-debuginfo-0.9.27-7.el10_2.2.s390x.rpm SHA-256: b746e12cd5f9f33b2b3bf682ef4bbfc9a2ab7feadd1aa56058dffec8c8391f86 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 s390x golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.s390x.rpm SHA-256: 8f6e8b9e67e323be814c50d9d0df230750cac79b359845b835cf1456cd8c6faa ipp-usb-0.9.27-7.el10_2.2.s390x.rpm SHA-256: e17f362b3e90086c01bd09905a847c2b3ae81e745f6a825e3ece05b6f8ba6e9a ipp-usb-debuginfo-0.9.27-7.el10_2.2.s390x.rpm SHA-256: b746e12cd5f9f33b2b3bf682ef4bbfc9a2ab7feadd1aa56058dffec8c8391f86 Red Hat Enterprise Linux for Power, little endian 10 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 ppc64le golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 22fef2d8d18e0c1128dc4cbb23961c989e35e810599daa4f157c71687632bb2d ipp-usb-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 6539bae3c73de1d6af44faf32865a420206da1b0400b61807a885b4d3360929e ipp-usb-debuginfo-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 966031f3618c91f17f54905ccfdd1a45ae38aff81cb24d2eae0b58718e48af86 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 ppc64le golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 22fef2d8d18e0c1128dc4cbb23961c989e35e810599daa4f157c71687632bb2d ipp-usb-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 6539bae3c73de1d6af44faf32865a420206da1b0400b61807a885b4d3360929e ipp-usb-debuginfo-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 966031f3618c91f17f54905ccfdd1a45ae38aff81cb24d2eae0b58718e48af86 Red Hat Enterprise Linux for ARM 64 10 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 aarch64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: 08559a6a893ae39248acd40f39542a714fc8cfaf5ac669b0a2705d62b9120b94 ipp-usb-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: f3ce1833c3265ba6d0b7603e6011610f4c9c1e9c3d8e05f597ffe4f971d84bab ipp-usb-debuginfo-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: a278096f59bd690bfd47334a8a1212433f2e8022ba23a44d45ae54414860f428 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 aarch64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: 08559a6a893ae39248acd40f39542a714fc8cfaf5ac669b0a2705d62b9120b94 ipp-usb-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: f3ce1833c3265ba6d0b7603e6011610f4c9c1e9c3d8e05f597ffe4f971d84bab ipp-usb-debuginfo-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: a278096f59bd690bfd47334a8a1212433f2e8022ba23a44d45ae54414860f428 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 aarch64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: 08559a6a893ae39248acd40f39542a714fc8cfaf5ac669b0a2705d62b9120b94 ipp-usb-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: f3ce1833c3265ba6d0b7603e6011610f4c9c1e9c3d8e05f597ffe4f971d84bab ipp-usb-debuginfo-0.9.27-7.el10_2.2.aarch64.rpm SHA-256: a278096f59bd690bfd47334a8a1212433f2e8022ba23a44d45ae54414860f428 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 s390x golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.s390x.rpm SHA-256: 8f6e8b9e67e323be814c50d9d0df230750cac79b359845b835cf1456cd8c6faa ipp-usb-0.9.27-7.el10_2.2.s390x.rpm SHA-256: e17f362b3e90086c01bd09905a847c2b3ae81e745f6a825e3ece05b6f8ba6e9a ipp-usb-debuginfo-0.9.27-7.el10_2.2.s390x.rpm SHA-256: b746e12cd5f9f33b2b3bf682ef4bbfc9a2ab7feadd1aa56058dffec8c8391f86 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 ppc64le golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 22fef2d8d18e0c1128dc4cbb23961c989e35e810599daa4f157c71687632bb2d ipp-usb-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 6539bae3c73de1d6af44faf32865a420206da1b0400b61807a885b4d3360929e ipp-usb-debuginfo-0.9.27-7.el10_2.2.ppc64le.rpm SHA-256: 966031f3618c91f17f54905ccfdd1a45ae38aff81cb24d2eae0b58718e48af86 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 SRPM golang-github-openprinting-ipp-usb-0.9.27-7.el10_2.2.src.rpm SHA-256: e95367259b2d7fe02a086996ae93bfa8c63cbba257c958c62cb7bffd8aac1905 x86_64 golang-github-openprinting-ipp-usb-debugsource-0.9.27-7.el10_2.2.x86_64.rpm SHA-256: d3b734cbdbf6ebe95abfc0a9853a43fef3036ab4de739ad5b278eb3f56351a55 ipp-usb-0.9
This security update addresses two denial-of-service vulnerabilities in the Go net and crypto/x509 packages, specifically CVE-2026-33811 (CVSS 7.5 HIGH) via long CNAME responses and CVE-2026-27145 (CVSS 6.5 MEDIUM) via excessive DNS SAN processing. The affected software is the `golang-github-openprinting-ipp-usb` package for Red Hat Enterprise Linux 10. The underlying Go runtime vulnerabilities affect Go versions prior to 1.25.10 and versions 1.26.0 through 1.26.2, which are fixed in Go 1.25.10 and 1.26.3 respectively.