Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:8841

Опубликовано: 21 апр. 2026
Источник: rocky
Оценка: Important

Описание

Important: go-rpm-macros security update

This package provides build-stage rpm automation to simplify the creation of Go language (golang) packages. It does not need to be included in the default build root: go-srpm-macros will pull it in for Go packages only.

Security Fix(es):

  • net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
go-filesystemx86_6414.el9_7go-filesystem-3.6.0-14.el9_7.x86_64.rpm
go-rpm-macrosx86_6414.el9_7go-rpm-macros-3.6.0-14.el9_7.x86_64.rpm
go-rpm-templatesnoarch14.el9_7go-rpm-templates-3.6.0-14.el9_7.noarch.rpm
go-srpm-macrosnoarch14.el9_7go-srpm-macros-3.6.0-14.el9_7.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

CVSS3: 7.5
redhat
4 месяца назад

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

CVSS3: 7.5
nvd
4 месяца назад

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

msrc
4 месяца назад

Incorrect parsing of IPv6 host literals in net/url

CVSS3: 7.5
debian
4 месяца назад

url.Parse insufficiently validated the host/authority component and ac ...