Описание
Important: golang security, bug fix, and enhancement update
The golang packages provide the Go programming language compiler.
Security Fix(es):
-
golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
-
os: golang: Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822)
Bug Fix(es) and Enhancement(s):
- Update Go to version 1.26.5+1 [rhel-9.8.z] (JIRA:Rocky Linux-193476)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Затронутые продукты
Rocky Linux 9
Связанные CVE
Исправления
- Red Hat - 2480756
- Red Hat - 2498152
Связанные уязвимости
ELSA-2026-37436: golang security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-37435: golang security, bug fix, and enhancement update (IMPORTANT)
Important: go-toolset:rhel8 security, bug fix, and enhancement update
ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT)