Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:47712: Important: golang security, bug fix, and enhancement update

This Red Hat Security Advisory addresses multiple vulnerabilities in the Go programming language (golang), including a critical TLS session resumption flaw (CVE-2025-68121, CVSS 10.0) allowing incorrect certificate validation, and several high-severity denial-of-service issues in crypto/x509 and crypto/tls. Affected versions are Go 1.24.x before 1.24.13, Go 1.25.x before 1.25.9, and Go 1.26.x before 1.26.2. The update resolves these by upgrading the provided packages to Go version 1.25.9+2 for RHEL 9.4 Update Services for SAP Solutions.
Read Full Article →

Red Hat Product Errata RHSA-2026:47712 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:47712 - Security Advisory Overview Updated Packages Synopsis Important: golang security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for golang is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The golang packages provide the Go programming language compiler. Security Fix(es): crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) golang: cmd/compile: no-op interface conversion bypasses overlap checking (CVE-2026-27144) golang: cmd/compile: possible memory corruption after bound check elimination (CVE-2026-27143) Bug Fix(es) and Enhancement(s): Update Go to version 1.25.9+2 [rhel-9.4.z] (JIRA:RHEL-178854) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building BZ - 2456340 - CVE-2026-27144 golang: cmd/compile: no-op interface conversion bypasses overlap checking BZ - 2456342 - CVE-2026-27143 golang: cmd/compile: possible memory corruption after bound check elimination RHEL-178854 - Update Go to version 1.25.9+2 [rhel-9.4.z] CVEs CVE-2025-68121 CVE-2026-27143 CVE-2026-27144 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e x86_64 go-toolset-1.25.9-1.el9_4.x86_64.rpm SHA-256: 5d443014b6562923ae8d0fb5ef49a910e095a71af713e61e7c8e3d3599e4b21c golang-1.25.9-1.el9_4.x86_64.rpm SHA-256: 3971bd8bed5305b7ed26a6abad280480555ee0b6ec8f9855fba1f434c9765380 golang-bin-1.25.9-1.el9_4.x86_64.rpm SHA-256: d88336cbdbd3bc35b4843c13f016368ffdff719ee018c34d5a76799211fd9693 golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9 golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3 golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e ppc64le go-toolset-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 975a1cbfc8990d36637bea3fde47af3e5a7f2e20d9c774f5dbc4224771d5677f golang-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 52ae595c56290b0a4cc5ba17e2ee943363777ef172836943f29b1d41390524d4 golang-bin-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 4e6f1613496a5380cc3c8fe9f93003b16f3d10b943c0b4878f2451b4fb461182 golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9 golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3 golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e x86_64 go-toolset-1.25.9-1.el9_4.x86_64.rpm SHA-256: 5d443014b6562923ae8d0fb5ef49a910e095a71af713e61e7c8e3d3599e4b21c golang-1.25.9-1.el9_4.x86_64.rpm SHA-256: 3971bd8bed5305b7ed26a6abad280480555ee0b6ec8f9855fba1f434c9765380 golang-bin-1.25.9-1.el9_4.x86_64.rpm SHA-256: d88336cbdbd3bc35b4843c13f016368ffdff719ee018c34d5a76799211fd9693 golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9 golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3 golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e aarch64 go-toolset-1.25.9-1.el9_4.aarch64.rpm SHA-256: cae72c703811c94753afc08f355cf7f5b6b4247c5817a72e245247824180b796 golang-1.25.9-1.el9_4.aarch64.rpm SHA-256: f87e4dd8de0d7d3f8998cb8c358bcd6315cd41a0f8cf863c694f7a3345d99f06 golang-bin-1.25.9-1.el9_4.aarch64.rpm SHA-256: 62b04c10cd26a6cafe2deccf08d99b1edb265b6c85ac49325dbac2304a23c8a7 golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9 golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3 golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e s390x go-toolset-1.25.9-1.el9_4.s390x.rpm SHA-256: 41c5cffdd9e65d7a316df167ff51047115e8acfe284a6aef130bee5c7d796cd2 golang-1.25.9-1.el9_4.s390x.rpm SHA-256: 1a9b331a3228d29268754bf4edefd00c8d3cd6839f17054b6da3191f62780a0b golang-bin-1.25.9-1.el9_4.s390x.rpm SHA-256: dbea9f29d4d714186988fce91273acfc6070aa430a331235646b9d32466d1482 golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9 golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3 golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e x86_64 go-toolset-1.25.9-1.el9_4.x86_64.rpm SHA-256: 5d443014b6562923ae8d0fb5ef49a910e095a71af713e61e7c8e3d3599e4b21c golang-1.25.9-1.el9_4.x86_64.rpm SHA-256: 3971bd8bed5305b7ed26a6abad280480555ee0b6ec8f9855fba1f434c9765380 golang-bin-1.25.9-1.el9_4.x86_64.rpm SHA-256: d88336cbdbd3bc35b4843c13f016368ffdff719ee018c34d5a76799211fd9693 golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9 golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3 golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 SRPM golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e aarch64 go-toolset-1.25.9-1.el9_4.aarch64.rpm SHA-256: cae72c703811c94753afc08f355cf7f5b6b4247c5817a72e245247824180b796 golang-1.25.9-1.el9_4.aarch64.rpm SHA-256: f87e4dd8de0d7d3f8998cb8c358bcd6315cd41a0f8cf863c69

Share this article