OPENSUSE-SU-2026:20570-1

Advisory lineage Upstream: 9 Downstream: 0
Published: 20 Apr 2026, 14:02
Last modified:22 Apr 2026, 18:27

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Apr 2026, 14:02
Published
Vulnerability first disclosed
22 Apr 2026, 18:27
Last Modified
Vulnerability information updated

Description

Security update for go1.25 This update for go1.25 fixes the following issues: - Update to version go1.25.9 (bsc#1244485). - CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653). - CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654). - CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking (bsc#1261655). - CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656). - CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657). - CVE-2026-32282: os: Root.Chmod can follow symlinks out of the root on Linux (bsc#1261658). - CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659). - CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660). - CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661).

Affected Systems

  • opensusego1.25&distro=openSUSE Leap 16.0

    < 1.25.9-160000.1.1

References (19)