[ALSA-2026:60306] Important: golang security, bug fix, and enhancement update
Type:
security
Severity:
important
Release date:
2026-08-27
Description:
The golang packages provide the Go programming language compiler. Security Fix(es): * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) Bug Fix(es) and Enhancement(s): * Update Go to version 1.26.7+1 [almalinux-10.2.z] (JIRA:AlmaLinux-246423) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 golang-race-1.26.7-1.el10_2.alma.1.aarch64.rpm 4ddd8a303ee6bbe7390d18b514f40da8a7faff9966d8c5676653986059b753f8
aarch64 go-toolset-1.26.7-1.el10_2.alma.1.aarch64.rpm 662797f2fed959ab8066c0859c88efb3f1a3d861460aa624ca37bc6efc7ce470
aarch64 golang-bin-1.26.7-1.el10_2.alma.1.aarch64.rpm 7194157827a7ea2047adee4864a0eb7aef1e42fbad49313a4f974e4cb2b0b371
aarch64 golang-1.26.7-1.el10_2.alma.1.aarch64.rpm 8fe1a12c99c3de63d57f3009bf6832f2e0e7d71e59b612fc6e4df35021c849a2
noarch golang-misc-1.26.7-1.el10_2.alma.1.noarch.rpm 1923dd6592518a5d2f4e4eef0ff7f7bf3b611a49230e03cd40caa092e84f83c5
noarch golang-tests-1.26.7-1.el10_2.alma.1.noarch.rpm 2cd7fa5d945a940c336d1817cb06f166edf8869a955ca3e7b5638d0f77886aea
noarch golang-docs-1.26.7-1.el10_2.alma.1.noarch.rpm 36167694db02b79aff2148f3934c8d4bd287c3615d93d5a40f6356796ff2e299
noarch golang-src-1.26.7-1.el10_2.alma.1.noarch.rpm db81e8b2dcb9cce76b60048edd375ec23e8fb6a055cbceb28ee21bb48274cc6e
ppc64le golang-bin-1.26.7-1.el10_2.alma.1.ppc64le.rpm 237f2f50db94c0194c4b3b7f2d9aeaf2a476d60bf77e1689ae0b2b553e98ca13
ppc64le golang-race-1.26.7-1.el10_2.alma.1.ppc64le.rpm 3a3f82c74c0d8d301c8e6bc8dbddf18eb1657dfa7717367f28289e7f5339252c
ppc64le go-toolset-1.26.7-1.el10_2.alma.1.ppc64le.rpm 660d9bd1e47a61f9119dda4baa059efc461d46fdbb1a7ea85371260d34b06f26
ppc64le golang-1.26.7-1.el10_2.alma.1.ppc64le.rpm ae788ac9314755828368da0a95c80f91e9b3678cf6f78ed4e22b5a96f98e9699
s390x go-toolset-1.26.7-1.el10_2.alma.1.s390x.rpm 868eaddc7c63ea2ee442acdd1d9d1357653eb0e14cd49cc67e5412f8c8b11dec
s390x golang-1.26.7-1.el10_2.alma.1.s390x.rpm af29fe51ef0af06896b6559ffa767b13681dad166d712f0899c5ba1d17ee9805
s390x golang-bin-1.26.7-1.el10_2.alma.1.s390x.rpm bf9fe3ae49bed7c8e1942f6ead4039aca35eb3a1fcc296dd8c790833952a6b7c
s390x golang-race-1.26.7-1.el10_2.alma.1.s390x.rpm cceb0038389f262b947d15ece6247745efdbf0a25f24845526ff187d60a0a92a
x86_64 golang-bin-1.26.7-1.el10_2.alma.1.x86_64.rpm 298d01ff427510db0b1c54740f88ff56cccee7b5e86e228d32a9521f46fea17d
x86_64 golang-1.26.7-1.el10_2.alma.1.x86_64.rpm 7892146acf13776d9d73e8d8edc979c21ae3624df6db90b7bb4a4b3e17b4902a
x86_64 go-toolset-1.26.7-1.el10_2.alma.1.x86_64.rpm c3b92180f6c6dc56fa8043fce9d72ca28b4914605d10abcda187088807c813b4
x86_64 golang-race-1.26.7-1.el10_2.alma.1.x86_64.rpm faf54974441ec3ef91539f16303c9c49c653d67aabeab27ef36c3b9b81abe112
x86_64_v2 golang-1.26.7-1.el10_2.alma.1.x86_64_v2.rpm 2ebf95fd9e8631ac843b41a40c18515c65e72ef9209233871ddc94407acbb3f8
x86_64_v2 golang-race-1.26.7-1.el10_2.alma.1.x86_64_v2.rpm 8b741f53c1421caf9ae067584bc0e5e4fdfbf27267192c4770043e9a970017bc
x86_64_v2 go-toolset-1.26.7-1.el10_2.alma.1.x86_64_v2.rpm d758ab466a82e3e01c8f21ad4b04bc101bacc936654b7c6b9e53d6f996330240
x86_64_v2 golang-bin-1.26.7-1.el10_2.alma.1.x86_64_v2.rpm f364b3570118b80208543122c4f589c0b72a1c9c82fadaa90caa3afbacee2789
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.