SUSE-CU-2026:6892-1: Security update of bci/golang

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 10 08:05:48 UTC 2026


SUSE Container Update Advisory: bci/golang
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:6892-1
Container Tags        : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.12 , bci/golang:1.25.12-2.76.6 , bci/golang:oldstable
Container Release     : 76.6
Severity              : important
Type                  : security
References            : 1244485 1245878 1259264 1259265 1259268 1264394 1271014 1271015
                        CVE-2026-25679 CVE-2026-27139 CVE-2026-27142 CVE-2026-39822 CVE-2026-42505
-----------------------------------------------------------------

The container bci/golang was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2817-1
Released:    Thu Jul  9 19:07:47 2026
Summary:     Security update for go1.25
Type:        security
Severity:    important
References:  1244485,1245878,1259264,1259265,1259268,1264394,1271014,1271015,CVE-2026-25679,CVE-2026-27139,CVE-2026-27142,CVE-2026-39822,CVE-2026-42505
This update for go1.25 fixes the following issues

- Update to version go1.25.12 (bsc#1244485).
- CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264).
- CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268).
- CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265).
- CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014).
- CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015).


The following package changes have been done:

- go1.25-doc-1.25.12-150000.1.44.1 updated
- go1.25-1.25.12-150000.1.44.1 updated
- go1.25-race-1.25.12-150000.1.44.1 updated


More information about the sle-container-updates mailing list