RHSA-2026:10704HighCVSS 9.0
Red Hat Security Advisory: go-toolset:rhel8 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-27140 — cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:10704
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456336
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456338
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456342
- externalhttps://issues.redhat.com/browse/RHEL-169932
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10704.json