golang-1.26.5-1.el9_8
エラータID: AXSA:2026-1485:08
The golang packages provide the Go programming language compiler.
Security Fix(es):
* golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
* os: golang: Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822)
Bug Fix(es) and Enhancement(s):
* Update Go to version 1.26.5+1 [rhel-9.8.z] (JIRA:RHEL-193476)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-39822
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
Update packages.
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
N/A
SRPMS
- golang-1.26.5-1.el9_8.src.rpm
MD5: 6ca8d9b1b1a61373171567babf24010a
SHA-256: f7eb8b3fff6615f429e1833bcb92c0650623ff56887d1d351c176c93c3ec80a3
Size: 34.82 MB
Asianux Server 9 for x86_64
- golang-1.26.5-1.el9_8.x86_64.rpm
MD5: 8b4d0acf13b5cbbb67cc911b5ce87cd3
SHA-256: 26b29e2ad0fe550f3d178495b72bbb62d3cf62c5b169485701a4d7d24048b504
Size: 1.44 MB - golang-bin-1.26.5-1.el9_8.x86_64.rpm
MD5: 2266e79d504ea23ea5a59f2b7086faad
SHA-256: 1582ebc17428208f28699af578c60146b5d9cba8e4192e46106c0e772bd6e5ea
Size: 44.12 MB - golang-docs-1.26.5-1.el9_8.noarch.rpm
MD5: d69b9cc028d0b2e62f58094d2007324b
SHA-256: e24127c5499c3c67dc103ba086d7e8db0f38a198a4c8c4072a72c699463880d6
Size: 108.52 kB - golang-misc-1.26.5-1.el9_8.noarch.rpm
MD5: 189a6a6e2f9935d8b5859998615a8e84
SHA-256: c68676a41b2226af667ea40fca08a754b979ea36a7e3a4717358fbc6a8da3522
Size: 41.16 kB - golang-race-1.26.5-1.el9_8.x86_64.rpm
MD5: 7ba33a1fe0c97a87b9b5dd553af80c22
SHA-256: 8d4fb9cd486149405552f9ab96cb2c4cbec1db04129874589036432b420ef711
Size: 1.66 MB - golang-src-1.26.5-1.el9_8.noarch.rpm
MD5: 2994c07925a8122538f2fad0fcdeabac
SHA-256: 08740e1375580ab26a8db98f9119ac2992294242c4296cef59749263c6294c47
Size: 12.09 MB - golang-tests-1.26.5-1.el9_8.noarch.rpm
MD5: 1aefda06b4cfb20a8da35ac7f768d9ca
SHA-256: b7202dc02e51af5dc0bc0b2d2470cae11c579b4deb00e69e2387769fb6a9697b
Size: 11.87 MB - go-toolset-1.26.5-1.el9_8.x86_64.rpm
MD5: 7b08ccd4dc6f05a4248b046ae2db05f0
SHA-256: 507c4997a408bf2a2fd88c16b8037707240d7554c09079455ca3687eb1a676e2
Size: 9.09 kB