Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21321-1

Опубликовано: 13 июл. 2026
Источник: suse-cvrf

Описание

Security update for go1.26-openssl

This update for go1.26-openssl fixes the following issues

  • Update to version go1.26.5 (bsc#1255111).
  • CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014).
  • CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015).

Список пакетов

openSUSE Leap 16.0
go1.26-openssl-1.26.5-160000.1.1
go1.26-openssl-doc-1.26.5-160000.1.1
go1.26-openssl-race-1.26.5-160000.1.1

Описание

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.


Затронутые продукты
openSUSE Leap 16.0:go1.26-openssl-1.26.5-160000.1.1
openSUSE Leap 16.0:go1.26-openssl-doc-1.26.5-160000.1.1
openSUSE Leap 16.0:go1.26-openssl-race-1.26.5-160000.1.1

Ссылки

Описание

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.


Затронутые продукты
openSUSE Leap 16.0:go1.26-openssl-1.26.5-160000.1.1
openSUSE Leap 16.0:go1.26-openssl-doc-1.26.5-160000.1.1
openSUSE Leap 16.0:go1.26-openssl-race-1.26.5-160000.1.1

Ссылки
Уязвимость openSUSE-SU-2026:21321-1