golang-1.26.7-1.el9_8
エラータID: AXSA:2026-1689:09
The golang packages provide the Go programming language compiler.
Security Fix(es):
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
Bug Fix(es) and Enhancement(s):
* Go 1.26 -- maxThreads limit hit in CGO threads blocked on RAND_bytes in FIPS mode (JIRA:RHEL-215845)
* Update Go to version 1.26.7+1 [rhel-9.8.z] (JIRA:RHEL-246425)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-33818
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
CVE-2026-56853
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
CVE-2026-56858
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
CVE-2026-56859
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
CVE-2026-56862
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.
Update packages.
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.
N/A
SRPMS
- golang-1.26.7-1.el9_8.src.rpm
MD5: 0fc123d8b65747f8b90c4086cd000bd4
SHA-256: 885a53f8798ceb634d71d1c232196a477eed2c3fe88546a0e5569c4345c09c50
Size: 34.84 MB
Asianux Server 9 for x86_64
- golang-1.26.7-1.el9_8.x86_64.rpm
MD5: 016ce04616d632ceb2ae2d0d9260b6e6
SHA-256: 0e3b7534a5b9179776a4dc4fb6e9cfc248a522dfd48bfd41f8846c5a141fb411
Size: 1.44 MB - golang-bin-1.26.7-1.el9_8.x86_64.rpm
MD5: 8efd96b45dfa1ca7d789728dbd00e1fa
SHA-256: 9c71ccf3ea8b59821ad54ad88d3f05c5a4537c134873a9b0691da7b8f1a295ee
Size: 45.00 MB - golang-docs-1.26.7-1.el9_8.noarch.rpm
MD5: 7548f7e5bb007d1d01916ef311c64cdc
SHA-256: 57845033db5a4927d195ad4c3334ada7e7e192b70785006d6245f4e1e89f752e
Size: 108.31 kB - golang-misc-1.26.7-1.el9_8.noarch.rpm
MD5: 02996cb8512e6c5d6f874b4c63855fd9
SHA-256: e86077635d391a9e0e8b365c240263434b2c40396c726db12564dbbbee36ccbe
Size: 40.92 kB - golang-race-1.26.7-1.el9_8.x86_64.rpm
MD5: aae3117a20e44df881b39f4337073867
SHA-256: a3d521c80f2d26a61d8f33fa3f2921af5b8f64dba974b517243af51f9ac5ff42
Size: 1.66 MB - golang-src-1.26.7-1.el9_8.noarch.rpm
MD5: a9200650eb50b4b77f2019896d82723f
SHA-256: 669853ddf4943f9e56b9172e7a1107030d9ea4ac6357ebfc1fddfb9de78dfaa6
Size: 12.09 MB - golang-tests-1.26.7-1.el9_8.noarch.rpm
MD5: 99bcb02459ed9423d60f9f8cb9b1f20a
SHA-256: 5c341c5e8b92b7d3743a8a536977bb55728b3e64abe9dd23dbd0387214e1b577
Size: 11.87 MB - go-toolset-1.26.7-1.el9_8.x86_64.rpm
MD5: 74b88fbd49a2142328b0359ac1b5f5e6
SHA-256: 132cffb585307b04c1524c0001e5da50a08c9a4d721c8de9719f3215cb405e60
Size: 8.86 kB