{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21254-1","published":"2026-07-07T16:57:26Z","modified":"2026-07-09T10:00:04.850998323Z","related":["CVE-2026-27140","CVE-2026-27143","CVE-2026-27144","CVE-2026-27145","CVE-2026-32280","CVE-2026-32281","CVE-2026-32282","CVE-2026-32283","CVE-2026-32288","CVE-2026-32289","CVE-2026-33810","CVE-2026-33811","CVE-2026-33814","CVE-2026-39817","CVE-2026-39819","CVE-2026-39820","CVE-2026-39823","CVE-2026-39825","CVE-2026-39826","CVE-2026-39836","CVE-2026-42499","CVE-2026-42501","CVE-2026-42504","CVE-2026-42507"],"upstream":["CVE-2026-27140","CVE-2026-27143","CVE-2026-27144","CVE-2026-27145","CVE-2026-32280","CVE-2026-32281","CVE-2026-32282","CVE-2026-32283","CVE-2026-32288","CVE-2026-32289","CVE-2026-33810","CVE-2026-33811","CVE-2026-33814","CVE-2026-39817","CVE-2026-39819","CVE-2026-39820","CVE-2026-39823","CVE-2026-39825","CVE-2026-39826","CVE-2026-39836","CVE-2026-42499","CVE-2026-42501","CVE-2026-42504","CVE-2026-42507"],"summary":"Security update for go1.26-openssl","details":"This update for go1.26-openssl fixes the following issues:\n\nUpdate to go1.26.4  (bsc#1255111).\n\nSecurity issues fixed:\n\n- CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653).\n- CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654).\n- CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking (bsc#1261655).\n- CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450).\n- CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656).\n- CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657).\n- CVE-2026-32282: os: `Root.Chmod` can follow symlinks out of the root on Linux (bsc#1261658).\n- CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659).\n- CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660).\n- CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661).\n- CVE-2026-33810: crypto/x509: excluded DNS constraints not properly applied to wildcard domains (bsc#1261662).\n- CVE-2026-33811: net: crash when handling long `CNAME` response (bsc#1264508).\n- CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` (bsc#1264506).\n- CVE-2026-39817: cmd/go: `go tool pack` does not sanitize output paths (bsc#1264505).\n- CVE-2026-39819: cmd/go: `go bug` follows symlinks in predictable temporary filenames (bsc#1264504).\n- CVE-2026-39820: net/mail: quadratic string concatentation in `consumeComment` (bsc#1264503).\n- CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509).\n- CVE-2026-39825: net/http/httputil: `ReverseProxy` forwards queries with more than `urlmaxqueryparams` parameters\n  (bsc#1264500).\n- CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507).\n- CVE-2026-39836: net: panic in `Dial` and `LookupPort` when handling `NUL` byte on Windows (bsc#1264501).\n- CVE-2026-42499: net/mail: quadratic string concatenation in `consumePhrase` (bsc#1264502).\n- CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499).\n- CVE-2026-42504: mime: quadratic complexity in `WordDecoder.DecodeHeader` (bsc#1267442).\n- CVE-2026-42507: net/textproto: arbitrary input is included in errors without any escaping (bsc#1267444).\n\nOther updates and security fixes:\n\n- Go packages miss `binutils-gold` dependency (bsc#1170826).\n- Drop subpackage `go1.x-libstd` `std` library `.so` refs (jsc#PED-1962).\n- Use `libalternatives` only on `suse_version >= 1610` and keep `update-alternatives` support for older\n  distributions.\n- Drop the `update-alternatives` migration path for `libalternatives` builds.\n- Enable `libalternatives` for SLE16.1 and Tumbleweed (bsc#1245878).\n- Drop go1.26 dependency on `update-alternatives` (bsc#1264395)\n- Update to version 1.26.3 cut from the `go1.25-fips-release` branch at the revision tagged `go1.26.3-1-openssl-fips`\n  (jsc#SLE-18320).\n","affected":[{"package":{"name":"go1.26-openssl","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/go1.26-openssl&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"go1.26-openssl":"1.26.4-160000.1.1","go1.26-openssl-doc":"1.26.4-160000.1.1","go1.26-openssl-race":"1.26.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21254-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170826"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255111"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261653"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261654"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261655"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261656"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261657"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261658"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261659"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261661"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261662"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264395"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264499"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264500"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264502"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264503"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264504"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264508"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264509"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267442"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267444"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27140"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27143"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27145"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32280"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32281"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32282"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32283"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32289"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33810"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33811"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39817"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39819"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39820"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39823"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39825"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39826"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39836"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42499"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42501"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42504"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42507"}]}