"go-toolset":"rhel8" delve-1.26.1-1.module+el8+2035+c232904f.ML.1, golang-1.26.7-1.module+el8+2035+c232904f.ML.1
エラータID: AXSA:2026-1726:01
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.
Security Fix(es):
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
Bug Fix(es) and Enhancement(s):
* Update Go to version 1.26.7+1 [rhel-8.10.z] (JIRA:RHEL-246426)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-33818
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
CVE-2026-56853
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
CVE-2026-56858
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
CVE-2026-56859
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
CVE-2026-56862
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.
Modularity name: "go-toolset"
Stream name: "rhel8"
Update packages.
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.
N/A
SRPMS
- delve-1.26.1-1.module+el8+2035+c232904f.ML.1.src.rpm
MD5: 843d1efc41a67c8a13184c44eabef7c7
SHA-256: 7f35a56a6a13ae13420f4498674604e6ee96f3b448fbcfebe90b06172d2905de
Size: 9.09 MB - golang-1.26.7-1.module+el8+2035+c232904f.ML.1.src.rpm
MD5: e5f3330f2723aca900b7d3bcb39cce3e
SHA-256: 01dc5dee5e9459f0f6ce5bbab2e04cbe0dafc9672ef53a8dc6bac234dce99f29
Size: 34.86 MB
Asianux Server 8 for x86_64
- delve-1.26.1-1.module+el8+2035+c232904f.ML.1.x86_64.rpm
MD5: 1bda66f6408a5efdf4e5e3b47b77c0b8
SHA-256: 448c550a88a97813ca230e55bd1cc3bb72719c63674537b21cfad0d88947b5ae
Size: 5.73 MB - delve-debugsource-1.26.1-1.module+el8+2035+c232904f.ML.1.x86_64.rpm
MD5: 2ac109f612eebc0c01707cdf474e8929
SHA-256: 177ff370ef6e7e181c7d6626da7f6ac2cf2ed4aabd0e82a78798647729a639eb
Size: 1.29 MB - golang-1.26.7-1.module+el8+2035+c232904f.ML.1.x86_64.rpm
MD5: 204ca17ed9b2fea39d91a129e7e2da0e
SHA-256: b215a54ab3c3626bcda57799f63911df0ae83009d5986fe8ce4b96808c213408
Size: 1.52 MB - golang-bin-1.26.7-1.module+el8+2035+c232904f.ML.1.x86_64.rpm
MD5: 952401d4e11631704424d0df851f8a40
SHA-256: ba424b8c71eae8f54f8427f14c17cc407815e25dcd23b04adfa2791e4f2a84cf
Size: 48.20 MB - golang-docs-1.26.7-1.module+el8+2035+c232904f.ML.1.noarch.rpm
MD5: 813210035ceee864513416ea68632d95
SHA-256: 6c6a2e9a53cfd1978ff513a62be11f62fcd9ce60060bfbef0be5ae0a0b688dc6
Size: 135.90 kB - golang-misc-1.26.7-1.module+el8+2035+c232904f.ML.1.noarch.rpm
MD5: 37e60dcb274c301fbe182f7c0e358397
SHA-256: 20fd232f27cd88a08b6db3b2631021b30804fa25ade62c25106acba512d5c14c
Size: 60.12 kB - golang-race-1.26.7-1.module+el8+2035+c232904f.ML.1.x86_64.rpm
MD5: 64f205e6a2bcd9f27743c4ae196c8537
SHA-256: d44ba641c80e1f4ae9f79f902a547535a0739fbab1a714f68f874a8d19eea437
Size: 1.27 MB - golang-src-1.26.7-1.module+el8+2035+c232904f.ML.1.noarch.rpm
MD5: 12a595792c62f74b65db050001c2f8c5
SHA-256: b854239a33facd37f922ddb2efe084f2d834c77f6db47b7c8b245688071b355b
Size: 12.24 MB - golang-tests-1.26.7-1.module+el8+2035+c232904f.ML.1.noarch.rpm
MD5: 224d89f25235667b88c23cc27be06791
SHA-256: 478a115719ac880e8ea14e7cb04b90d301801cc8c9e36455b8988b55ce63aa86
Size: 11.31 MB - go-toolset-1.26.7-1.module+el8+2035+c232904f.ML.1.x86_64.rpm
MD5: 494b02757564e63a0c7288047825d60a
SHA-256: 28db94301677fe3d66a3ec97765b8674943d57bf2d8b4ccfac09b7c03c4419a2
Size: 33.66 kB