SUSE-CU-2026:7396-1: Security update of bci/golang

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sun Jul 26 08:18:46 UTC 2026


SUSE Container Update Advisory: bci/golang
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7396-1
Container Tags        : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.5-openssl , bci/golang:1.26.5-openssl-89.15 , bci/golang:latest , bci/golang:stable-openssl
Container Release     : 89.15
Severity              : important
Type                  : security
References            : 1245878 1252306 1253043 1255111 1257463 1264395 1267442 1267444
                        1267450 1271014 1271015 CVE-2026-27145 CVE-2026-39822 CVE-2026-42504
                        CVE-2026-42505 CVE-2026-42507 
-----------------------------------------------------------------

The container bci/golang was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3102-1
Released:    Fri Jul 17 15:10:30 2026
Summary:     Security update for go1.26-openssl
Type:        security
Severity:    important
References:  1245878,1255111,1264395,1267442,1267444,1267450,1271014,1271015,CVE-2026-27145,CVE-2026-39822,CVE-2026-42504,CVE-2026-42505,CVE-2026-42507
This update for go1.26-openssl fixes the following issues

- Update to version go1.26.5 (bsc#1255111).
- CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450).
- CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014).
- CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442).
- CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015).
- CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released:    Fri Jul 17 22:18:41 2026
Summary:     Recommended update for gcc15
Type:        recommended
Severity:    moderate
References:  1252306,1253043,1257463
This update for gcc15 fixes the following issues:

- Update to GCC 15.3 release 

- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
  versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t.  Filter out -Wtime_t-conversion
  from flags to build D target library files. [jsc#PED-15601] 
- Remove loongarch64 from quadmath_arch. On LoongArch long double
  is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
  even when not available at build time.  [bsc#1253043] 
- Backport fix that cures a miscompile of libgo on arm.  [bsc#1252306]
- Check availability of builtins at expand time

The following package changes have been done:

- glibc-2.38-150600.14.52.1 updated
- go1.26-openssl-doc-1.26.5-150600.13.9.1 updated
- libatomic1-15.3.0+git11272-150000.1.12.1 updated
- libgomp1-15.3.0+git11272-150000.1.12.1 updated
- libitm1-15.3.0+git11272-150000.1.12.1 updated
- liblsan0-15.3.0+git11272-150000.1.12.1 updated
- go1.26-openssl-1.26.5-150600.13.9.1 updated
- go1.26-openssl-race-1.26.5-150600.13.9.1 updated
- container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated


More information about the sle-container-updates mailing list