SUSE-CU-2026:6895-1: Security update of bci/golang

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 10 08:07:45 UTC 2026


SUSE Container Update Advisory: bci/golang
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:6895-1
Container Tags        : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.5 , bci/golang:1.26.5-1.75.6 , bci/golang:latest , bci/golang:stable
Container Release     : 75.6
Severity              : important
Type                  : security
References            : 1245878 1255111 1264395 1271014 1271015 CVE-2026-39822 CVE-2026-42505
-----------------------------------------------------------------

The container bci/golang was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2818-1
Released:    Thu Jul  9 19:09:01 2026
Summary:     Security update for go1.26
Type:        security
Severity:    important
References:  1245878,1255111,1264395,1271014,1271015,CVE-2026-39822,CVE-2026-42505
This update for go1.26 fixes the following issues

- Update to version go1.26.5 (bsc#1255111)
- CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014).
- CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015).


The following package changes have been done:

- go1.26-doc-1.26.5-150000.1.18.1 updated
- go1.26-1.26.5-150000.1.18.1 updated
- go1.26-race-1.26.5-150000.1.18.1 updated


More information about the sle-container-updates mailing list