Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:47719: Important: golang security, bug fix, and enhancement update

This Red Hat advisory addresses multiple security vulnerabilities in the Go compiler (golang), including a critical TLS session resumption flaw (CVE-2025-68121, CVSS 10.0) allowing incorrect certificate validation, and several high-severity denial-of-service issues in crypto/x509 and crypto/tls. Affected versions include Go versions prior to 1.24.13, 1.25.0 through 1.25.6, and 1.26.0; specific fixes are provided in Go 1.24.13, 1.25.7, and 1.25.9. The update for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions upgrades the package to Go version 1.25.9+2 to remediate these issues.
Read Full Article →

Red Hat Product Errata RHSA-2026:47719 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:47719 - Security Advisory Overview Updated Packages Synopsis Important: golang security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for golang is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The golang packages provide the Go programming language compiler. Security Fix(es): crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) golang: cmd/compile: no-op interface conversion bypasses overlap checking (CVE-2026-27144) golang: cmd/compile: possible memory corruption after bound check elimination (CVE-2026-27143) Bug Fix(es) and Enhancement(s): Update Go to version 1.25.9+2 [rhel-9.2.z] (JIRA:RHEL-182118) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building BZ - 2456340 - CVE-2026-27144 golang: cmd/compile: no-op interface conversion bypasses overlap checking BZ - 2456342 - CVE-2026-27143 golang: cmd/compile: possible memory corruption after bound check elimination RHEL-182118 - Update Go to version 1.25.9+2 [rhel-9.2.z] CVEs CVE-2025-68121 CVE-2026-27143 CVE-2026-27144 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM golang-1.25.9-1.el9_2.src.rpm SHA-256: 2916a585b275479cc563117cefe9d469bbfca15fae81ab16694774061a54731a x86_64 go-toolset-1.25.9-1.el9_2.x86_64.rpm SHA-256: 2d22d9409a7962a19f633ccfc043544373796212a6086bc2dd4c492594f3cab0 golang-1.25.9-1.el9_2.x86_64.rpm SHA-256: d45870163406c932426d4624e56071e13f547ca1f96429db3a918dba59aebde3 golang-bin-1.25.9-1.el9_2.x86_64.rpm SHA-256: 9fbd2249ff8d59c0d1aff117b7b6407a3f44e7f9414030eb9d041fa383c6210d golang-docs-1.25.9-1.el9_2.noarch.rpm SHA-256: 92481f552c4d13e932aebd354d416505a8f4f7c3611c6de3370813b3896cf3de golang-misc-1.25.9-1.el9_2.noarch.rpm SHA-256: 05b7888992b30312e28e6a28cb2b6607de8e2781226ee879d379cb722e9e2a3e golang-race-1.25.9-1.el9_2.x86_64.rpm SHA-256: 6b129f2cffa966a11f21ca6b8bc12685d56735ba1b450308c2344752c4d11ff0 golang-src-1.25.9-1.el9_2.noarch.rpm SHA-256: 61f6ec1b98d153bc3c020426f7f34147810e8d018d71b5d817d197c272a9998c golang-tests-1.25.9-1.el9_2.noarch.rpm SHA-256: 1e4ba6aaecd96462fe5ef95ada9f8cff1493aa919ac41b127dd11d63bccd7edf Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM golang-1.25.9-1.el9_2.src.rpm SHA-256: 2916a585b275479cc563117cefe9d469bbfca15fae81ab16694774061a54731a ppc64le go-toolset-1.25.9-1.el9_2.ppc64le.rpm SHA-256: 214a7b8da530db4a39b9ddc877ac483797e397e02b544894c217110c965551ae golang-1.25.9-1.el9_2.ppc64le.rpm SHA-256: 350753874b024d546954d5f34637caa726260d7af0707a71d8b29d1c8c118c74 golang-bin-1.25.9-1.el9_2.ppc64le.rpm SHA-256: 130c0377a60be6beb859c6575c98ae26c4c3a9dc24943d45ea6dd7ad0aeaa98d golang-docs-1.25.9-1.el9_2.noarch.rpm SHA-256: 92481f552c4d13e932aebd354d416505a8f4f7c3611c6de3370813b3896cf3de golang-misc-1.25.9-1.el9_2.noarch.rpm SHA-256: 05b7888992b30312e28e6a28cb2b6607de8e2781226ee879d379cb722e9e2a3e golang-src-1.25.9-1.el9_2.noarch.rpm SHA-256: 61f6ec1b98d153bc3c020426f7f34147810e8d018d71b5d817d197c272a9998c golang-tests-1.25.9-1.el9_2.noarch.rpm SHA-256: 1e4ba6aaecd96462fe5ef95ada9f8cff1493aa919ac41b127dd11d63bccd7edf Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM golang-1.25.9-1.el9_2.src.rpm SHA-256: 2916a585b275479cc563117cefe9d469bbfca15fae81ab16694774061a54731a x86_64 go-toolset-1.25.9-1.el9_2.x86_64.rpm SHA-256: 2d22d9409a7962a19f633ccfc043544373796212a6086bc2dd4c492594f3cab0 golang-1.25.9-1.el9_2.x86_64.rpm SHA-256: d45870163406c932426d4624e56071e13f547ca1f96429db3a918dba59aebde3 golang-bin-1.25.9-1.el9_2.x86_64.rpm SHA-256: 9fbd2249ff8d59c0d1aff117b7b6407a3f44e7f9414030eb9d041fa383c6210d golang-docs-1.25.9-1.el9_2.noarch.rpm SHA-256: 92481f552c4d13e932aebd354d416505a8f4f7c3611c6de3370813b3896cf3de golang-misc-1.25.9-1.el9_2.noarch.rpm SHA-256: 05b7888992b30312e28e6a28cb2b6607de8e2781226ee879d379cb722e9e2a3e golang-race-1.25.9-1.el9_2.x86_64.rpm SHA-256: 6b129f2cffa966a11f21ca6b8bc12685d56735ba1b450308c2344752c4d11ff0 golang-src-1.25.9-1.el9_2.noarch.rpm SHA-256: 61f6ec1b98d153bc3c020426f7f34147810e8d018d71b5d817d197c272a9998c golang-tests-1.25.9-1.el9_2.noarch.rpm SHA-256: 1e4ba6aaecd96462fe5ef95ada9f8cff1493aa919ac41b127dd11d63bccd7edf Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM golang-1.25.9-1.el9_2.src.rpm SHA-256: 2916a585b275479cc563117cefe9d469bbfca15fae81ab16694774061a54731a aarch64 go-toolset-1.25.9-1.el9_2.aarch64.rpm SHA-256: de9196cb19867c42554a563ed8e1f31663e3e02d99dc1fabe2c55b9c913c50b5 golang-1.25.9-1.el9_2.aarch64.rpm SHA-256: 33fb49ca8aaef561e94d9ebda360abd23ba79995120b3e49acd20da3eb339f75 golang-bin-1.25.9-1.el9_2.aarch64.rpm SHA-256: 5691562f22a5eb0bc31c0c8fd495f9de254710c19363be1836daa9dc06ac9f22 golang-docs-1.25.9-1.el9_2.noarch.rpm SHA-256: 92481f552c4d13e932aebd354d416505a8f4f7c3611c6de3370813b3896cf3de golang-misc-1.25.9-1.el9_2.noarch.rpm SHA-256: 05b7888992b30312e28e6a28cb2b6607de8e2781226ee879d379cb722e9e2a3e golang-src-1.25.9-1.el9_2.noarch.rpm SHA-256: 61f6ec1b98d153bc3c020426f7f34147810e8d018d71b5d817d197c272a9998c golang-tests-1.25.9-1.el9_2.noarch.rpm SHA-256: 1e4ba6aaecd96462fe5ef95ada9f8cff1493aa919ac41b127dd11d63bccd7edf Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 SRPM golang-1.25.9-1.el9_2.src.rpm SHA-256: 2916a585b275479cc563117cefe9d469bbfca15fae81ab16694774061a54731a s390x go-toolset-1.25.9-1.el9_2.s390x.rpm SHA-256: 800ee888252d250a414e672193582ec959a0193f36bc4175862963ce4f46637b golang-1.25.9-1.el9_2.s390x.rpm SHA-256: 617bee8db30b8dafdd989839bd6231cc2b386b37f48ae005bce704d8a5540e9e golang-bin-1.25.9-1.el9_2.s390x.rpm SHA-256: 15db25eb7bbbc66fe7f24d6a481ae221b32a4cc8c5e43b260c75dc9fabecaa1c golang-docs-1.25.9-1.el9_2.noarch.rpm SHA-256: 92481f552c4d13e932aebd354d416505a8f4f7c3611c6de3370813b3896cf3de golang-misc-1.25.9-1.el9_2.noarch.rpm SHA-256: 05b7888992b30312e28e6a28cb2b6607de8e2781226ee879d379cb722e9e2a3e golang-src-1.25.9-1.el9_2.noarch.rpm SHA-256: 61f6ec1b98d153bc3c020426f7f34147810e8d018d71b5d817d197c272a9998c golang-tests-1.25.9-1.el9_2.noarch.rpm SHA-256: 1e4ba6aaecd96462fe5ef95ada9f8cff1493aa919ac41b127dd11d63bccd7edf Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 SRPM golang-1.25.9-1.el9_2.src.rpm SHA-256: 2916a585b275479cc563117cefe9d469bbfca15fae81ab16694774061a54731a x86_64 go-toolset-1.25.9-1.el9_2.x86_64.rpm SHA-256: 2d22d9409a7962a19f633ccfc043544373796212a6086bc2dd4c492594f3cab0 golang-1.25.9-1.el9_2.x86_64.rpm SHA-256: d45870163406c932426d4624e56071e13f547ca1f96429db3a918dba59aebde3 golang-bin-1.25.9-1.el9_2.x86_64.rpm SHA-256: 9fbd2249ff8d59c0d1aff117b7b6407a3f44e7f9414030eb9d041fa383c6210d golang-docs-1.25.9-1.el9_2.noarch.rpm SHA-256: 92481f552c4d13e932aebd354d416505a8f4f7c3611c6de3370813b3896cf3de golang-misc-1.25.9-1.el9_2.noarch.rpm SHA-256: 05b7888992b30312e28e6a28cb2b6607de8e2781226ee879d379cb722e9e2a3e golang-race-1.25.9-1.el9_2.x86_64.rpm SHA-256: 6b129f2cffa966a11f21ca6b8bc12685d56735ba1b450308c2344752c4d11ff0 golang-src-1.25.9-1.el9_2.noarch.rpm SHA-256: 61f6ec1b98d153bc3c020426f7f34147810e8d018d71b5d817d197c272a9998c golang-tests-1.25.9-1.el9_2.noarch.rpm SHA-256: 1e4ba6aaecd96462fe5ef95ada9f8cff1493aa919ac41b127dd11d63bccd7edf Red Hat Enterprise Linux for ARM 64 - Extended L

Share this article