openSUSE-SU-2026:21254-1: important: Security update for go1.26-openssl

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for go1.26-openssl
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21254-1
Rating: important
References:

  * bsc#1170826
  * bsc#1245878
  * bsc#1255111
  * bsc#1261653
  * bsc#1261654
  * bsc#1261655
  * bsc#1261656
  * bsc#1261657
  * bsc#1261658
  * bsc#1261659
  * bsc#1261660
  * bsc#1261661
  * bsc#1261662
  * bsc#1264395
  * bsc#1264499
  * bsc#1264500
  * bsc#1264501
  * bsc#1264502
  * bsc#1264503
  * bsc#1264504
  * bsc#1264505
  * bsc#1264506
  * bsc#1264507
  * bsc#1264508
  * bsc#1264509
  * bsc#1267442
  * bsc#1267444
  * bsc#1267450



Cross-References:

  * CVE-2026-27140
  * CVE-2026-27143
  * CVE-2026-27144
  * CVE-2026-27145
  * CVE-2026-32280
  * CVE-2026-32281
  * CVE-2026-32282
  * CVE-2026-32283
  * CVE-2026-32288
  * CVE-2026-32289
  * CVE-2026-33810
  * CVE-2026-33811
  * CVE-2026-33814
  * CVE-2026-39817
  * CVE-2026-39819
  * CVE-2026-39820
  * CVE-2026-39823
  * CVE-2026-39825
  * CVE-2026-39826
  * CVE-2026-39836
  * CVE-2026-42499
  * CVE-2026-42501
  * CVE-2026-42504
  * CVE-2026-42507



CVSS scores:

  * CVE-2026-27140 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-27143 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-27144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
  * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-32280 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-32281 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-32282 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-32283 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-32288 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
  * CVE-2026-32289 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-33810 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-33811 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-39817 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
  * CVE-2026-39819 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
  * CVE-2026-39820 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-39823 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-39825 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-39826 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-39836 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-42499 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-42501 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 24 vulnerabilities and has 28 bug fixes can now be installed.

Description:

This update for go1.26-openssl fixes the following issues:

Update to go1.26.4  (bsc#1255111).

Security issues fixed:

- CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653).
- CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654).
- CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking (bsc#1261655).
- CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450).
- CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656).
- CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657).
- CVE-2026-32282: os: `Root.Chmod` can follow symlinks out of the root on Linux (bsc#1261658).
- CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659).
- CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660).
- CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661).
- CVE-2026-33810: crypto/x509: excluded DNS constraints not properly applied to wildcard domains (bsc#1261662).
- CVE-2026-33811: net: crash when handling long `CNAME` response (bsc#1264508).
- CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` (bsc#1264506).
- CVE-2026-39817: cmd/go: `go tool pack` does not sanitize output paths (bsc#1264505).
- CVE-2026-39819: cmd/go: `go bug` follows symlinks in predictable temporary filenames (bsc#1264504).
- CVE-2026-39820: net/mail: quadratic string concatentation in `consumeComment` (bsc#1264503).
- CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509).
- CVE-2026-39825: net/http/httputil: `ReverseProxy` forwards queries with more than `urlmaxqueryparams` parameters
  (bsc#1264500).
- CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507).
- CVE-2026-39836: net: panic in `Dial` and `LookupPort` when handling `NUL` byte on Windows (bsc#1264501).
- CVE-2026-42499: net/mail: quadratic string concatenation in `consumePhrase` (bsc#1264502).
- CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499).
- CVE-2026-42504: mime: quadratic complexity in `WordDecoder.DecodeHeader` (bsc#1267442).
- CVE-2026-42507: net/textproto: arbitrary input is included in errors without any escaping (bsc#1267444).

Other updates and security fixes:

- Go packages miss `binutils-gold` dependency (bsc#1170826).
- Drop subpackage `go1.x-libstd` `std` library `.so` refs (jsc#PED-1962).
- Use `libalternatives` only on `suse_version >= 1610` and keep `update-alternatives` support for older
  distributions.
- Drop the `update-alternatives` migration path for `libalternatives` builds.
- Enable `libalternatives` for SLE16.1 and Tumbleweed (bsc#1245878).
- Drop go1.26 dependency on `update-alternatives` (bsc#1264395)
- Update to version 1.26.3 cut from the `go1.25-fips-release` branch at the revision tagged `go1.26.3-1-openssl-fips`
  (jsc#SLE-18320).


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1175=1

Package List:

- openSUSE Leap 16.0:

  go1.26-openssl-1.26.4-160000.1.1
  go1.26-openssl-doc-1.26.4-160000.1.1
  go1.26-openssl-race-1.26.4-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-27140.html
  * https://www.suse.com/security/cve/CVE-2026-27143.html
  * https://www.suse.com/security/cve/CVE-2026-27144.html
  * https://www.suse.com/security/cve/CVE-2026-27145.html
  * https://www.suse.com/security/cve/CVE-2026-32280.html
  * https://www.suse.com/security/cve/CVE-2026-32281.html
  * https://www.suse.com/security/cve/CVE-2026-32282.html
  * https://www.suse.com/security/cve/CVE-2026-32283.html
  * https://www.suse.com/security/cve/CVE-2026-32288.html
  * https://www.suse.com/security/cve/CVE-2026-32289.html
  * https://www.suse.com/security/cve/CVE-2026-33810.html
  * https://www.suse.com/security/cve/CVE-2026-33811.html
  * https://www.suse.com/security/cve/CVE-2026-33814.html
  * https://www.suse.com/security/cve/CVE-2026-39817.html
  * https://www.suse.com/security/cve/CVE-2026-39819.html
  * https://www.suse.com/security/cve/CVE-2026-39820.html
  * https://www.suse.com/security/cve/CVE-2026-39823.html
  * https://www.suse.com/security/cve/CVE-2026-39825.html
  * https://www.suse.com/security/cve/CVE-2026-39826.html
  * https://www.suse.com/security/cve/CVE-2026-39836.html
  * https://www.suse.com/security/cve/CVE-2026-42499.html
  * https://www.suse.com/security/cve/CVE-2026-42501.html
  * https://www.suse.com/security/cve/CVE-2026-42504.html
  * https://www.suse.com/security/cve/CVE-2026-42507.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.