[ALSA-2026:60304] Important: golang security, bug fix, and enhancement update
Type:
security
Severity:
important
Release date:
2026-08-27
Description:
The golang packages provide the Go programming language compiler. Security Fix(es): * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) Bug Fix(es) and Enhancement(s): * Go 1.26 -- maxThreads limit hit in CGO threads blocked on RAND_bytes in FIPS mode (JIRA:AlmaLinux-215845) * Update Go to version 1.26.7+1 [almalinux-9.8.z] (JIRA:AlmaLinux-246425) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 golang-race-1.26.7-1.el9_8.aarch64.rpm 0107d3853722bc2ed31e2416be5b010fe199c0184de6388cf573b737f8e183be
aarch64 go-toolset-1.26.7-1.el9_8.aarch64.rpm 0d5dc210da14bcb8ddc9190d2da0d5dd82dc1a528fb3de7c575ce4421185f969
aarch64 golang-bin-1.26.7-1.el9_8.aarch64.rpm 610c9d5528dfcdcf7787fd8d171779e1c5b073769acf40763f65ab92416e2afe
aarch64 golang-1.26.7-1.el9_8.aarch64.rpm f667cee5043a462d7e7ee3b4a8c0a3b485915e1ab6e61db3ee66ba1a8b8ef516
noarch golang-tests-1.26.7-1.el9_8.noarch.rpm 14565ae19f03ef4227d82ce3e4030df52c335f26e02d86d40ec0fd398b774d22
noarch golang-misc-1.26.7-1.el9_8.noarch.rpm 178902393cee6104035c55b9908d625f2a8470f53a6e7ccc120fa9d86cad8b36
noarch golang-src-1.26.7-1.el9_8.noarch.rpm 5ecf0e5a09fbe760b856ca58376955d75fa597b3f82e28aa2df227a620012cee
noarch golang-docs-1.26.7-1.el9_8.noarch.rpm 700d9e89173b96cfbdaea70b82bb4cec4428ef2addc69f9e4d8dc3e2ba2a367a
ppc64le golang-race-1.26.7-1.el9_8.ppc64le.rpm 198a6787bfb6d6e6ebe5cf4d3ae3607fe0dcec03d79e4d0d576efcfb10008034
ppc64le go-toolset-1.26.7-1.el9_8.ppc64le.rpm 28970c2c16c2169c2fba069589b3ce38eb4b31589199610138f423895ee72c74
ppc64le golang-bin-1.26.7-1.el9_8.ppc64le.rpm c60196fe4b553b88176a77136ef567ebeba295b81a14b96f48c5d9af2807cdc6
ppc64le golang-1.26.7-1.el9_8.ppc64le.rpm ea99a72628c5fa2491402a9f8e138e672cb600c433b85817e08608250b730cd6
s390x golang-race-1.26.7-1.el9_8.s390x.rpm 2996325e7078877a176617281ca7e43c80020d8bb70c903573743272a0db6d9b
s390x golang-1.26.7-1.el9_8.s390x.rpm 69d700af93baba5805992db806c185f73918f186fb0685ff66b11ce5c8bacfba
s390x go-toolset-1.26.7-1.el9_8.s390x.rpm 7225377e548b52f4d6c2df636f7d92358d6fed4b886959a2098d90edbc1d1acb
s390x golang-bin-1.26.7-1.el9_8.s390x.rpm ce4eff47ce225d1ce5ef12bafc84744a9ae9967655159cb957724b8bdce8dc35
x86_64 golang-bin-1.26.7-1.el9_8.x86_64.rpm 2f9251481565a04fd9971362563062656ebbc7e3617611d864fd9e22ed2dc819
x86_64 go-toolset-1.26.7-1.el9_8.x86_64.rpm 871e494399d1c9ba1b03f797461a0de85f9455b4d35f5ebfe3df8e218b43f5dd
x86_64 golang-race-1.26.7-1.el9_8.x86_64.rpm 8acf0770938bc52e198cf1149bb3d4f93e56f6f48bbf887800efb4d7e44e139f
x86_64 golang-1.26.7-1.el9_8.x86_64.rpm 919fbc82132dc4b9a0321cbce11b64b084691f8b7f7fff3e458a52f19d2d0668
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.