Release date:
2026-08-29 10:26:29 UTC
Description:
- CVE-2026-33818: encoding/asn1 - enforce a maximum recursion depth in
parseField and parseSequenceOf, so a deeply nested crafted DER payload can
no longer exhaust the stack while unmarshalling
- CVE-2026-56862: crypto/tls - only treat application data, and handshake
records seen before the handshake completes, as state-advancing, so a peer
can no longer spam post-handshake KeyUpdate messages to force unbounded key
derivation
- CVE-2026-56860: net/url - resolve reference paths on a byte buffer with
index-based backtracking instead of rebuilding a string on every ".."
segment, removing the quadratic time and allocation cost
- CVE-2026-56859: encoding/xml - track unmarshal depth on the decoder stack
instead of a local counter that DecodeElement reset, so a custom
UnmarshalXML implementation can no longer bypass the depth limit and
exhaust the stack
- CVE-2026-56858: html/template - keep the JavaScript regexp/division context
up to date across brace transitions, so pathological input can no longer
close an unescaped '/' early and inject arbitrary content
Updated packages:
-
go-toolset-1.22.9-1.el9_2.tuxcare.els26.x86_64.rpm
sha:a97cae3ba02c43c719003438c57dc22168e45aa91d38f9a0546ab847fd5b94cd
-
golang-1.22.9-1.el9_2.tuxcare.els26.x86_64.rpm
sha:500e36610732954b5d4ea7b0617d7bb1b4776c5a1b6234c17d46f2aab2fbd4d2
-
golang-bin-1.22.9-1.el9_2.tuxcare.els26.x86_64.rpm
sha:1d92e06021422ddbe4021d7f3d190a8269f8a9b1f6664b4bd6299a4bf31fa331
-
golang-docs-1.22.9-1.el9_2.tuxcare.els26.noarch.rpm
sha:909f0efe035e407119c6b235534ccb99a3b931645dd35ac11e39bd7dabc70cd0
-
golang-misc-1.22.9-1.el9_2.tuxcare.els26.noarch.rpm
sha:9999d9d2aa39d315d6e16506e701bba563387c488e20065e063d2f810b51a81b
-
golang-src-1.22.9-1.el9_2.tuxcare.els26.noarch.rpm
sha:6ac140f325acb11457a5bb991c5049b9cb7dab2d0c893af238c4e9b3895a51cf
-
golang-tests-1.22.9-1.el9_2.tuxcare.els26.noarch.rpm
sha:45a45d25106c496f5c61b667dcc899598bf17c4e9a6dd8e84cc38c42de338157
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.