OPENSUSE-SU-2026:21592-1

Advisory lineage Upstream: 9 Downstream: 0
Published: 19 Aug 2026, 09:07
Last modified:21 Aug 2026, 09:15

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Aug 2026, 09:07
Published
Vulnerability first disclosed
21 Aug 2026, 09:15
Last Modified
Vulnerability information updated

Description

Security update for go1.25 This update for go1.25 fixes the following issues: Update to go1.25.13 (released 2026-08-13, bsc#1244485). Security issues fixed: - CVE-2026-33818: encoding/asn1: unenforced recursion limit can lead to stack exhaustion when parsing deeply-nested, recursive structures (bsc#1275034). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609). - CVE-2026-56853: net/http: missing timeout when doing unencrypted HTTP/2 check can lead to a denial of service (bsc#1275028). - CVE-2026-56858: html/template: improper Javascript regexp context tracking allows for XSS attacks (bsc#1275033). - CVE-2026-56859: encoding/xml: missing recursion depth guard during decode operation can lead to stack exhaustion and a denial of service (bsc#1275026). - CVE-2026-56860: net/url: quadratic time complexity in `resolvePath` when processing certain input can lead to high memory allocation overhead and a denial of service (bsc#1275029). - CVE-2026-56862: crypto/tls: no limit set for handshake messages sent post-handshake allows for denial of service (bsc#1275032). - CVE-2026-56864: x/mod/sumdb: unauthenticated hashes accepted in `Lookup` allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content (bsc#1275025). - CVE-2026-56865: x/mod/sumdb/tlog: improper transparency log tile verification allows for bypass on crafted input and can lead to malicious module content to be accepted (bsc#1275024). Changes for go1.25.13: - go#79875 cmd/compile: prove misscompilation in slicemask folding leaves garbage in upper bits - go#80098 cmd/compile: internal compiler error invalid heap allocated var without Heapaddr - go#80364 os: Root's MkdirAll can't create paths ending in forward slashes - go#80366 os: TestRootMultiReadFile fails on netbsd/arm64 after CL 797880 - go#80368 os: TestRootConsistencyRemoveAll fails on Plan 9 after CL 797880 - go#80393 runtime: arm64 found pointer to free object with safe code - go#80440 runtime: uninitialized register due to wrong ABI in mach_vm_region_trampoline leads to libc following garbage stack data as a pointer - go#80477 cmd/compile: riscv64 miscompiles struct copy, corrupting a []byte slice field - go#80500 runtime: js/wasm: "found bad pointer in Go heap" -- link-layout-constant value recorded as a pointer in the write-barrier buffer - go#80578 cmd/compile: regalloc uses unreliable type data (like v.Type.IsSigned()) to choose the restore of spills - go#80605 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement - go#80614 cmd/compile: mips64le misscompile OffPtr by a const which doesn't fit 32bits resulting in panic - go#80616 cmd/compile: mips/mips64, multiply/divide results spilled from HI/LO corrupted w/ big stack frames - go#80618 cmd/compile: prove bug causes invalid indirect call - go#80737 runtime: fpTracebackPartialExpand SIGSEGV under high panic load

Affected Systems

  • opensusego1.25&distro=openSUSE Leap 16.0

    < 1.25.13-160000.1.1

References (19)