Red Hat Product Errata RHSA-2026:37436 - Security Advisory Issued: 2026-07-09 Updated: 2026-07-09 RHSA-2026:37436 - Security Advisory Overview Updated Packages Synopsis Important: golang security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for golang is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The golang packages provide the Go programming language compiler. Security Fix(es): golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) os: golang: Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822) Bug Fix(es) and Enhancement(s): Update Go to version 1.26.5+1 [rhel-10.2.z] (JIRA:RHEL-193473) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing RHEL-193473 - Update Go to version 1.26.5+1 [rhel-10.2.z] CVEs CVE-2026-39821 CVE-2026-39822 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM golang-1.26.5-1.el10_2.src.rpm SHA-256: 9467c2daf35c25ddf55c38cd999d8bd4984221736aecf955cbd678b02da8c14b x86_64 go-toolset-1.26.5-1.el10_2.x86_64.rpm SHA-256: 987ddbacff895f0aa5b70926eb8904dc7c3c29bbf43a58f91c9dd2d893a9e173 golang-1.26.5-1.el10_2.x86_64.rpm SHA-256: 23f554e49fa116e27d47315309a5181c77bbe39470ca4bc82a1ac283bb53ff83 golang-bin-1.26.5-1.el10_2.x86_64.rpm SHA-256: 1e096f101c584e97cd03624f5459b6e272ddff64b5a083b1299d287a952c311c golang-docs-1.26.5-1.el10_2.noarch.rpm SHA-256: a2741211b688ddadb2d2f535e5c48d4129c0cea8a58f05fff0033a3bbf70446c golang-misc-1.26.5-1.el10_2.noarch.rpm SHA-256: 6a5b06c8756a4a5199afd3cf487aa47e8d23518eccf89186c0962970f0535212 golang-race-1.26.5-1.el10_2.x86_64.rpm SHA-256: b0b111a91a2c185305488f0b425565ee32dba50342d01df85f9b4b14bca4f208 golang-src-1.26.5-1.el10_2.noarch.rpm SHA-256: 40e82554e70b8da9fe64f3e600494cffc43ed906e6afd18c319b54c42dcfe796 golang-tests-1.26.5-1.el10_2.noarch.rpm SHA-256: a93748c61fb8aaeaa7a748bbc7392c64c26da64f10530daea07004899c766a3b Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM golang-1.26.5-1.el10_2.src.rpm SHA-256: 9467c2daf35c25ddf55c38cd999d8bd4984221736aecf955cbd678b02da8c14b x86_64 go-toolset-1.26.5-1.el10_2.x86_64.rpm SHA-256: 987ddbacff895f0aa5b70926eb8904dc7c3c29bbf43a58f91c9dd2d893a9e173 golang-1.26.5-1.el10_2.x86_64.rpm SHA-256: 23f554e49fa116e27d47315309a5181c77bbe39470ca4bc82a1ac283bb53ff83 golang-bin-1.26.5-1.el10_2.x86_64.rpm SHA-256: 1e096f101c584e97cd03624f5459b6e272ddff64b5a083b1299d287a952c311c golang-docs-1.26.5-1.el10_2.noarch.rpm SHA-256: a2741211b688ddadb2d2f535e5c48d4129c0cea8a58f05fff0033a3bbf70446c golang-misc-1.26.5-1.el10_2.noarch.rpm SHA-256: 6a5b06c8756a4a5199afd3cf487aa47e8d23518eccf89186c0962970f0535212 golang-race-1.26.5-1.el10_2.x86_64.rpm SHA-256: b0b111a91a2c185305488f0b425565ee32dba50342d01df85f9b4b14bca4f208 golang-src-1.26.5-1.el10_2.noarch.rpm SHA-256: 40e82554e70b8da9fe64f3e600494cffc43ed906e6afd18c319b54c42dcfe796 golang-tests-1.26.5-1.el10_2.noarch.rpm SHA-256: a93748c61fb8aaeaa7a748bbc7392c64c26da64f10530daea07004899c766a3b Red Hat Enterprise Linux for IBM z Systems 10 SRPM golang-1.26.5-1.el10_2.src.rpm SHA-256: 9467c2daf35c25ddf55c38cd999d8bd4984221736aecf955cbd678b02da8c14b s390x go-toolset-1.26.5-1.el10_2.s390x.rpm SHA-256: 42e9e543933f1e2bf7d482d6f362b6b004c370b728fd2b4c5875d9379a90fc5a golang-1.26.5-1.el10_2.s390x.rpm SHA-256: ef5318cc4c4996c5450621556df21caf835fdc8a334f6093f0962e5aefa746b5 golang-bin-1.26.5-1.el10_2.s390x.rpm SHA-256: 5cc4521c850d70ca7694b046ba13bab7828903cb676b2d270e7cbfeeba8678fb golang-docs-1.26.5-1.el10_2.noarch.rpm SHA-256: a2741211b688ddadb2d2f535e5c48d4129c0cea8a58f05fff0033a3bbf70446c golang-misc-1.26.5-1.el10_2.noarch.rpm SHA-256: 6a5b06c8756a4a5199afd3cf487aa47e8d23518eccf89186c0962970f0535212 golang-race-1.26.5-1.el10_2.s390x.rpm SHA-256: 592911b3847de90f3a7e661041bf452fb1c2c24a2e39728e7897fbf43c478b73 golang-src-1.26.5-1.el10_2.noarch.rpm SHA-256: 40e82554e70b8da9fe64f3e600494cffc43ed906e6afd18c319b54c42dcfe796 golang-tests-1.26.5-1.el10_2.noarch.rpm SHA-256: a93748c61fb8aaeaa7a748bbc7392c64c26da64f10530daea07004899c766a3b Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM golang-1.26.5-1.el10_2.src.rpm SHA-256: 9467c2daf35c25ddf55c38cd999d8bd4984221736aecf955cbd678b02da8c14b s390x go-toolset-1.26.5-1.el10_2.s390x.rpm SHA-256: 42e9e543933f1e2bf7d482d6f362b6b004c370b728fd2b4c5875d9379a90fc5a golang-1.26.5-1.el10_2.s390x.rpm SHA-256: ef5318cc4c4996c5450621556df21caf835fdc8a334f6093f0962e5aefa746b5 golang-bin-1.26.5-1.el10_2.s390x.rpm SHA-256: 5cc4521c850d70ca7694b046ba13bab7828903cb676b2d270e7cbfeeba8678fb golang-docs-1.26.5-1.el10_2.noarch.rpm SHA-256: a2741211b688ddadb2d2f535e5c48d4129c0cea8a58f05fff0033a3bbf70446c golang-misc-1.26.5-1.el10_2.noarch.rpm SHA-256: 6a5b06c8756a4a5199afd3cf487aa47e8d23518eccf89186c0962970f0535212 golang-race-1.26.5-1.el10_2.s390x.rpm SHA-256: 592911b3847de90f3a7e661041bf452fb1c2c24a2e39728e7897fbf43c478b73 golang-src-1.26.5-1.el10_2.noarch.rpm SHA-256: 40e82554e70b8da9fe64f3e600494cffc43ed906e6afd18c319b54c42dcfe796 golang-tests-1.26.5-1.el10_2.noarch.rpm SHA-256: a93748c61fb8aaeaa7a748bbc7392c64c26da64f10530daea07004899c766a3b Red Hat Enterprise Linux for Power, little endian 10 SRPM golang-1.26.5-1.el10_2.src.rpm SHA-256: 9467c2daf35c25ddf55c38cd999d8bd4984221736aecf955cbd678b02da8c14b ppc64le go-toolset-1.26.5-1.el10_2.ppc64le.rpm SHA-256: 228e8910f6188184854d0975703d326899685d0d0c52c3fa394e2465252fd1f9 golang-1.26.5-1.el10_2.ppc64le.rpm SHA-256: da143d1af3b266402f47582cb754db6709a3ad4e5df82af38862b4d422f20c17 golang-bin-1.26.5-1.el10_2.ppc64le.rpm SHA-256: 19701a3d11d221de2509259491ace1d2d461f51be6ae114474582b25b2eb40d6 golang-docs-1.26.5-1.el10_2.noarch.rpm SHA-256: a2741211b688ddadb2d2f535e5c48d4129c0cea8a58f05fff0033a3bbf70446c golang-misc-1.26.5-1.el10_2.noarch.rpm SHA-256: 6a5b06c8756a4a5199afd3cf487aa47e8d23518eccf89186c0962970f0535212 golang-race-1.26.5-1.el10_2.ppc64le.rpm SHA-256: 0323e92db4e11ae37eff188d79d8e002dbcad929a6540bdf9af5e9580b76bfbc golang-src-1.26.5-1.el10_2.noarch.rpm SHA-256: 40e82554e70b8da9fe64f3e600494cffc43ed906e6afd18c319b54c42dcfe796 golang-tests-1.26.5-1.el10_2.noarch.rpm SHA-256: a93748c61fb8aaeaa7a748bbc7392c64c26da64f10530daea07004899c766a3b Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM golang-1.26.5-1.el10_2.src.rpm SHA-256: 9467c2daf35c25ddf55c38cd999d8bd4984221736aecf955cbd678b02da8c14b ppc64le go-toolset-1.26.5-1.el10_2.ppc64le.rpm SHA-256: 228e8910f6188184854d0975703d326899685d0d0c52c3fa394e2465252fd1f9 golang-1.26.5-1.el10_2.ppc64le.rpm SHA-256: da143d1af3b266402f47582cb754db6709a3ad4e5df82af38862b4d422f20c17 golang-bin-1.26.5-1.el10_2.ppc64le.rpm SHA-256: 19701a3d11d221de2509259491ace1d2d461f51be6ae114474582b25b2eb40d6 golang-docs-1.26.5-1.el10_2.noarch.rpm SHA-256: a2741211b688ddadb2d2f535e5c48d4129c0cea8a58f05fff0033a3bbf70446c golang-misc-1.26.5-1.el10_2.noarch.rpm SHA-256: 6a5b06c8756a4a5199afd3cf487aa47e8d23518eccf89186c0962970f0535212 golang-race-1.26.5-1.el10_2.ppc64le.rpm SHA-256: 0323e92db4e11ae37eff188d79d8e002dbcad929a6540bdf9af5e9580b76bfbc golang-src-1.26.5-1.el10_2.noarch.rpm SHA-256: 40e82554e70b8da9fe64f3e600494cffc43ed906e6afd18c319b54c42dcfe796 golang-tests-1.26.5-1.el10_2.noarch.rpm SHA-256: a93748c61fb8aaeaa7a748bbc7392c64c26da64f10530daea07004899c766a3b Red Hat Enterprise Linux for ARM 64 10 SRPM golang-1.26.5-1.el10_2.src.rpm SHA-256: 9467c2daf35c25ddf55c38cd999d8bd4984221736aecf955cbd678b02da8c14b aarch64 go-toolset-1.26.5-1.el10_2.aarch64.rpm SHA-256: cb99682636501cc1c4b5f218b2347d81dcbfab9879dd60873c51b894f58290b5 golang-1.26.5-1.el10_2.aarch64.rpm SHA-256: 18b99a77ecdc67207e824f4e28657660580c5f0f470aab760b771c210c262c2d golang-bin-1.26.5-1.el10_2.aarch64.rpm SHA-256: 908a5521b013590903b43af1c0194e2b79c2fb480eb42e170ee8c78782e9
This Red Hat security advisory addresses two Important Go vulnerabilities: CVE-2026-39821, a critical (CVSS 9.6) privilege escalation flaw in the `golang.org/x/net/idna` library due to incorrect Punycode label processing, and CVE-2026-39822, a high-severity directory traversal vulnerability in `os.Root` caused by symlink following. The NVD data indicates that versions of the `golang.org/x/net` module prior to 0.55.0 are affected by CVE-2026-39821. The fix is provided by updating the Go compiler packages to version 1.26.5+1 for Red Hat Enterprise Linux 10.2.z.