[CLSA-2026:1787999176] golang: Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-29 10:26:29 UTC
Description:
- CVE-2026-33818: encoding/asn1 - enforce a maximum recursion depth in parseField and parseSequenceOf, so a deeply nested crafted DER payload can no longer exhaust the stack while unmarshalling - CVE-2026-56862: crypto/tls - only treat application data, and handshake records seen before the handshake completes, as state-advancing, so a peer can no longer spam post-handshake KeyUpdate messages to force unbounded key derivation - CVE-2026-56860: net/url - resolve reference paths on a byte buffer with index-based backtracking instead of rebuilding a string on every ".." segment, removing the quadratic time and allocation cost - CVE-2026-56859: encoding/xml - track unmarshal depth on the decoder stack instead of a local counter that DecodeElement reset, so a custom UnmarshalXML implementation can no longer bypass the depth limit and exhaust the stack - CVE-2026-56858: html/template - keep the JavaScript regexp/division context up to date across brace transitions, so pathological input can no longer close an unescaped '/' early and inject arbitrary content
Updated packages:
  • go-toolset-1.22.9-1.el9_2.tuxcare.els26.x86_64.rpm
    sha:a97cae3ba02c43c719003438c57dc22168e45aa91d38f9a0546ab847fd5b94cd
  • golang-1.22.9-1.el9_2.tuxcare.els26.x86_64.rpm
    sha:500e36610732954b5d4ea7b0617d7bb1b4776c5a1b6234c17d46f2aab2fbd4d2
  • golang-bin-1.22.9-1.el9_2.tuxcare.els26.x86_64.rpm
    sha:1d92e06021422ddbe4021d7f3d190a8269f8a9b1f6664b4bd6299a4bf31fa331
  • golang-docs-1.22.9-1.el9_2.tuxcare.els26.noarch.rpm
    sha:909f0efe035e407119c6b235534ccb99a3b931645dd35ac11e39bd7dabc70cd0
  • golang-misc-1.22.9-1.el9_2.tuxcare.els26.noarch.rpm
    sha:9999d9d2aa39d315d6e16506e701bba563387c488e20065e063d2f810b51a81b
  • golang-src-1.22.9-1.el9_2.tuxcare.els26.noarch.rpm
    sha:6ac140f325acb11457a5bb991c5049b9cb7dab2d0c893af238c4e9b3895a51cf
  • golang-tests-1.22.9-1.el9_2.tuxcare.els26.noarch.rpm
    sha:45a45d25106c496f5c61b667dcc899598bf17c4e9a6dd8e84cc38c42de338157
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.