[ALSA-2026:3864] Important: delve security update
Type:
security
Severity:
important
Release date:
2026-03-06
Description:
Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible. Security Fix(es): * crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) * golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) * crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 delve-1.25.2-2.el10_1.aarch64.rpm 083c0f45bae9067a9faf5e03ed7c9d5497652f22538409e434cb80a612120004
ppc64le delve-1.25.2-2.el10_1.ppc64le.rpm cb23a5a1b635ba2245ef469b3795a7fe1ac5fdfd41d78997858480c13a44cfac
x86_64 delve-1.25.2-2.el10_1.x86_64.rpm 1bef27c4138733dfa376a9b6a3c3823ea531b928c79caa55d9c522acdb0f982c
x86_64_v2 delve-1.25.2-2.el10_1.x86_64_v2.rpm 3bb401d93851db3a40b32621621d46ee3a9ba3e3ab6b4f6802124e19fd89d2a3
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.