SUSE-CU-2025:8924-1: Security update of bci/golang

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Dec 12 10:21:09 UTC 2025


SUSE Container Update Advisory: bci/golang
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2025:8924-1
Container Tags        : bci/golang:1.25 , bci/golang:1.25.5 , bci/golang:1.25.5-1.76.11 , bci/golang:latest , bci/golang:stable , bci/golang:stable-1.76.11
Container Release     : 76.11
Severity              : important
Type                  : security
References            : 1244485 1245878 1254227 1254430 1254431 CVE-2025-61727 CVE-2025-61729
-----------------------------------------------------------------

The container bci/golang was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4336-1
Released:    Wed Dec 10 00:50:02 2025
Summary:     Security update for go1.25
Type:        security
Severity:    important
References:  1244485,1245878,1254227,1254430,1254431,CVE-2025-61727,CVE-2025-61729
This update for go1.25 fixes the following issues:

go1.25.5 (released 2025-12-02) includes two security fixes to the
crypto/x509 package, as well as bug fixes to the mime and os
packages.
(bsc#1244485)

  CVE-2025-61729 CVE-2025-61727:

  * go#76461 go#76445 bsc#1254431 security: fix CVE-2025-61729 crypto/x509: excessive resource consumption in printing error string for host certificate validation
  * go#76464 go#76442 bsc#1254430 security: fix CVE-2025-61727 crypto/x509: excluded subdomain constraint doesn't preclude wildcard SAN
  * go#76245 mime: FormatMediaType and ParseMediaType not compatible across 1.24 to 1.25
  * go#76360 os: on windows RemoveAll removing directories containing read-only files errors with unlinkat ... Access is denied, ReOpenFile error handling followup

- Packaging: Migrate from update-alternatives to libalternatives (bsc#1245878)

  * This is an optional migration controlled via prjconf definition
    with_libalternatives
  * If with_libalternatives is not defined packaging continues to
    use update-alternatives

go1.25.4 (released 2025-11-05) includes fixes to the compiler,
the runtime, and the crypto/subtle, encoding/pem, net/url, and os
packages. (bsc#1244485)

  * go#75480 cmd/link: linker panic and relocation errors with complex generics inlining
  * go#75775 runtime: build fails when run via QEMU for linux/amd64 running on linux/arm64
  * go#75790 crypto/internal/fips140/subtle: Go 1.25 subtle.xorBytes panic on MIPS
  * go#75832 net/url: ipv4 mapped ipv6 addresses should be valid in square brackets
  * go#75952 encoding/pem: regression when decoding blocks with leading garbage
  * go#75989 os: on windows RemoveAll removing directories containing read-only files errors with unlinkat ... Access is denied
  * go#76010 cmd/compile: any(func(){})==any(func(){}) does not panic but should
  * go#76029 pem/encoding: malformed line endings can cause panics


The following package changes have been done:

- go1.25-doc-1.25.5-150000.1.23.1 updated
- go1.25-1.25.5-150000.1.23.1 updated
- go1.25-race-1.25.5-150000.1.23.1 updated


More information about the sle-container-updates mailing list