SUSE-CU-2026:7394-1: Security update of bci/golang

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sun Jul 26 08:16:29 UTC 2026


SUSE Container Update Advisory: bci/golang
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7394-1
Container Tags        : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.12-openssl , bci/golang:1.25.12-openssl-89.19 , bci/golang:oldstable-openssl
Container Release     : 89.19
Severity              : important
Type                  : security
References            : 1244485 1245878 1259264 1259265 1259268 1262684 1264394 1267442
                        1267444 1267450 1271014 1271015 CVE-2026-25679 CVE-2026-27139
                        CVE-2026-27142 CVE-2026-27145 CVE-2026-39822 CVE-2026-41989 CVE-2026-42504
                        CVE-2026-42505 CVE-2026-42507 
-----------------------------------------------------------------

The container bci/golang was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3151-1
Released:    Tue Jul 21 14:48:45 2026
Summary:     Security update for go1.25-openssl
Type:        security
Severity:    important
References:  1244485,1245878,1259264,1259265,1259268,1264394,1267442,1267444,1267450,1271014,1271015,CVE-2026-25679,CVE-2026-27139,CVE-2026-27142,CVE-2026-27145,CVE-2026-39822,CVE-2026-42504,CVE-2026-42505,CVE-2026-42507
This update for go1.25-openssl fixes the following issues

- Update to version go1.25.12 (bsc#1244485).
- CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264).
- CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268).
- CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265).
- CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450).
- CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014).
- CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442).
- CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015).
- CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3182-1
Released:    Wed Jul 22 09:25:44 2026
Summary:     Security update for libgcrypt
Type:        security
Severity:    moderate
References:  1262684,CVE-2026-41989
This update for libgcrypt fixes the following issue

- CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service
  (bsc#1262684).


The following package changes have been done:

- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- go1.25-openssl-doc-1.25.12-150600.13.21.1 updated
- go1.25-openssl-1.25.12-150600.13.21.1 updated
- go1.25-openssl-race-1.25.12-150600.13.21.1 updated
- container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated


More information about the sle-container-updates mailing list