Описание
Security update for go1.26
This update for go1.26 fixes the following issues
- Update to version go1.26.5 (bsc#1255111).
- CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014).
- CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015).
Список пакетов
openSUSE Leap 16.0
go1.26-1.26.5-160000.1.1
go1.26-doc-1.26.5-160000.1.1
go1.26-race-1.26.5-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1245878
- SUSE Bug 1255111
- SUSE Bug 1264395
- SUSE Bug 1271014
- SUSE Bug 1271015
- SUSE CVE CVE-2026-39822 page
- SUSE CVE CVE-2026-42505 page
Описание
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
Затронутые продукты
openSUSE Leap 16.0:go1.26-1.26.5-160000.1.1
openSUSE Leap 16.0:go1.26-doc-1.26.5-160000.1.1
openSUSE Leap 16.0:go1.26-race-1.26.5-160000.1.1
Ссылки
- CVE-2026-39822
- SUSE Bug 1271014
Описание
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
Затронутые продукты
openSUSE Leap 16.0:go1.26-1.26.5-160000.1.1
openSUSE Leap 16.0:go1.26-doc-1.26.5-160000.1.1
openSUSE Leap 16.0:go1.26-race-1.26.5-160000.1.1
Ссылки
- CVE-2026-42505
- SUSE Bug 1271015