|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:21705-1 (go1.26-openssl)

From:  null@suse.de
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:21705-1: important: Security update for go1.26-openssl
Date:  Mon, 31 Aug 2026 17:57:33 +0200
Message-ID:  <20260831155734.04C7CFDCF@maintenance.suse.de>
Archive-link:  Article

openSUSE security update: security update for go1.26-openssl ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21705-1 Rating: important References: * bsc#1255111 * bsc#1266609 * bsc#1275024 * bsc#1275025 * bsc#1275026 * bsc#1275028 * bsc#1275029 * bsc#1275032 * bsc#1275033 * bsc#1275034 Cross-References: * CVE-2026-33818 * CVE-2026-39821 * CVE-2026-56853 * CVE-2026-56858 * CVE-2026-56859 * CVE-2026-56860 * CVE-2026-56862 * CVE-2026-56864 * CVE-2026-56865 CVSS scores: * CVE-2026-33818 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56853 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56858 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-56859 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56860 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56862 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56864 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56865 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 9 vulnerabilities and has 10 bug fixes can now be installed. Description: This update for go1.26-openssl fixes the following issues: Update to version 1.26.7 cut from the go1.25-fips-release branch at the revision tagged go1.26.7-1-openssl-fips. Security issues fixed: - CVE-2026-33818: encoding/asn1: stack exhaustion when parsing deeply-nested, recursive structures can lead to denial of service (bsc#1275034). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609). - CVE-2026-56853: net/http: first header read timeout not being applied when a server is configured to support unencrypted HTTP/2 allows for denial of service (bsc#1275028). - CVE-2026-56858: html/template: wrong JavaScript regexp context tracking after top-level `{` can lead to XSS (bsc#1275033). - CVE-2026-56859: encoding/xml: stack exhaustion due to recursion depth guard bypass during decoding operations can lead to denial of service (bsc#1275026). - CVE-2026-56860: net/url: quadratic complexity in `resolvePath` when processing backtrack path elements can lead to denial of service (bsc#1275029). - CVE-2026-56862: crypto/tls: handshake messages can bypass non-advancing record limit in TLS 1.3, which can lead to a denial of service (bsc#1275032). - CVE-2026-56864: x/mod/sumdb: a malicious `GOSUMDB` is capable of serving arbitrary module content not contained within the transparency log (bsc#1275025). - CVE-2026-56865: x/mod/sumdb/tlog: a malicious `GOPROXY` is capable of forging sumdb tiles, which allows for bypass of the `GOSUMDB` check and persistence of attacker-controlled module contents to a local Go module cache (bsc#1275024). Other updates and bugfixes: - Update to version 1.26.7 cut from the go1.25-fips-release branch at the revision tagged go1.26.7-1-openssl-fips: (jsc#SLE-18320). * Rebase to 1.26.7 * Support `strictfipsruntime` with `no_openssl` * Fix multiple `no_openssl` build tag issues - go1.26.7 (released 2026-08-19, boo#1255111): * go#80927 net/http: `ReadHeaderTimeout` remains active after unencrypted `HTTP/2` handoff - go1.26.6 (released 2026-08-13): * includes security fixes to the `go` command, and the `crypto/tls`, `encoding/asn1`, `encoding/xml`, `html/template`, `net`, `net/http`, and `net/url` packages, as well as bug fixes to the compiler, the linker, the runtime, and the `crypto/tls` and `os` packages. * go#79876 cmd/compile: `prove` misscompilation in `slicemask` folding leaves garbage in the upper bits * go#80099 cmd/compile: internal compiler error invalid heap allocated var without `Heapaddr` * go#80131 cmd/link: `peCreateExportFile` generates invalid `.def` file when output name has trailing dot (`c-shared` on Windows) * go#80365 os: `Root`'s `MkdirAll` can't create paths ending in forward slashes * go#80367 os: `TestRootMultiReadFile` fails on `netbsd/arm64` after CL 797880 * go#80369 os: `TestRootConsistencyRemoveAll` fails on Plan 9 after CL 797880 * go#80394 runtime: `arm64` found pointer to free object with safe code * go#80441 runtime: uninitialized register due to wrong ABI in `mach_vm_region_trampoline` leads to `libc` following garbage stack data as a pointer * go#80478 cmd/compile: `riscv64` miscompiles struct copy, corrupting a `[]byte` slice field * go#80499 runtime: js/wasm: "found bad pointer in Go heap" -- link-layout-constant value recorded as a pointer in the write-barrier buffer * go#80579 cmd/compile: `regalloc` uses unreliable type data (like `v.Type.IsSigned()`) to choose the restore of spills * go#80606 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement * go#80609 net, x/net/dns/dnsmessage: panic when parsing invalid `SVCB` record * go#80615 cmd/compile: `mips64le` misscompile `OffPtr` by a const which doesn't fit 32bits resulting in panic * go#80617 cmd/compile: `mips`/`mips64`, multiply/divide results spilled from `HI`/`LO` corrupted w/ big stack frames * go#80619 cmd/compile: `prove` bug causes invalid indirect call * go#80715 runtime: `fpTracebackPartialExpand` `SIGSEGV` under high panic load - Update to version 1.26.5 cut from the go1.25-fips-release branch at the revision tagged go1.26.5-2-openssl-fips: * Limit `openssl` `RandReader` concurrency Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1561=1 Package List: - openSUSE Leap 16.0: go1.26-openssl-1.26.7-160000.1.1 go1.26-openssl-doc-1.26.7-160000.1.1 go1.26-openssl-race-1.26.7-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-33818.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56853.html * https://www.suse.com/security/cve/CVE-2026-56858.html * https://www.suse.com/security/cve/CVE-2026-56859.html * https://www.suse.com/security/cve/CVE-2026-56860.html * https://www.suse.com/security/cve/CVE-2026-56862.html * https://www.suse.com/security/cve/CVE-2026-56864.html * https://www.suse.com/security/cve/CVE-2026-56865.html


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds