SUSE-CU-2026:7964-1: Security update of bci/golang

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Aug 5 07:47:35 UTC 2026


SUSE Container Update Advisory: bci/golang
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7964-1
Container Tags        : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.5 , bci/golang:1.26.5-1.75.27 , bci/golang:latest , bci/golang:stable
Container Release     : 75.27
Severity              : moderate
Type                  : security
References            : 1245878 1247816 1248082 1264390 1264391 1264392 1264393 1264394
                        1264395 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468
                        CVE-2026-40553 
-----------------------------------------------------------------

The container bci/golang was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3444-1
Released:    Fri Jul 31 22:04:31 2026
Summary:     Security update for openssl-3
Type:        security
Severity:    moderate
References:  1271712
This update for openssl-3 fixes the following issues:

- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
  (bsc#1271712).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3455-1
Released:    Mon Aug  3 13:46:45 2026
Summary:     Security update for gawk
Type:        security
Severity:    moderate
References:  1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553
This update for gawk fixes the following issues:

- CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351).
- CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352).
- CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3481-1
Released:    Tue Aug  4 13:44:40 2026
Summary:     Recommended update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl
Type:        recommended
Severity:    moderate
References:  1245878,1247816,1248082,1264390,1264391,1264392,1264393,1264394,1264395
This update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl fixes the following issues:

- Packaging improvements:

  * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install
    of a working go command. Refs bsc#1245878 bsc#1264390
  * Based on feedback from Factory maintainers restore the original
    lifecycle for these files: Each go1.x toolchain shares
    ownership of a go and gofmt symlink managed by the alternatives
    system (update-alternatives and libalternatives). When the last
    go1.x package is uninstalled the symlinks will be removed.
  * Context: %ghost was introduced to prevent file conflicts among
    go1.x toolchain packages reported by installcheck dev tool.
    %ghost prevents the files from being installed, which results
    in no installed go command. The shared ownership of the go and
    gofmt symlinks is intentional.
  * Define go_bootstrap_version with digits without go1.x prefix.
    Correct path spelling to align with current toolchain layout
    GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version},
    noting interstitial /go/ in path. Fixes bootstrap
    ERROR: Cannot find /usr/lib64/go1.x/bin/go.
    Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y.
    Bootstrap error first observed when using %ghost /usr/bin/go.
    Fixed by Eugenio Paolantonio. Refs bsc#1245878 bsc#1264390
  * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts
    among go1.x toolchain packages. These files are managed by the
    alternatives system. Refs bsc#1245878 bsc#1264390
  * Drop unused conditional %define with_shared refs jsc#PED-1962
  * Uniqify %define go_libalternatives 1219 to accommodate parallel
    installed toolchain variants per go1.x major version.
    go1.x has highest alternatives priority and uses suffix 9.
    refs bsc#1245878 bsc#1264390
  * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962
  * Use of Go standard library as .so and -buildmode=shared is not
    recommended or supported by upstream Go
  * Subpackage go1.x-libstd was only ever built for Factory and
    removal does not affect SLE
  * No Go application packages in Factory use go1.x-libstd
- Use libalternatives only on suse_version >= 1610 and keep
  update-alternatives support for older distributions.
- Drop the update-alternatives migration path for libalternatives builds.
- Packaging: Enable libalternatives for SLE16.1 and Tumbleweed
  Refs bsc#1245878
  * Drop go1.21 dependency on update-alternatives fixes bsc#1264390
- Prepare for removing old go versions from Factory:
  * Switch default for go1.21 to bootstrap with gcc-go using
    %bcond_without gccgo_go121
  * Building go1.21 with gcc-go by default removes need for prjconf
  * Refs bsc#1247816 bootstrap go1.21 with gccgo


The following package changes have been done:

- libopenssl3-3.2.3-150700.5.40.1 updated
- libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated
- go1.26-doc-1.26.5-150000.1.21.1 updated
- gawk-4.2.1-150000.3.6.1 updated
- go1.26-1.26.5-150000.1.21.1 updated
- go1.26-race-1.26.5-150000.1.21.1 updated
- container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated


More information about the sle-container-updates mailing list