Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:10217 - Security Advisory
Issued:
2026-04-23
Updated:
2026-04-23

RHSA-2026:10217 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: golang security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for golang is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The golang packages provide the Go programming language compiler.

Security Fix(es):

  • golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
  • crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
  • crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
  • golang: cmd/compile: no-op interface conversion bypasses overlap checking (CVE-2026-27144)
  • cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names (CVE-2026-27140)
  • golang: cmd/compile: possible memory corruption after bound check elimination (CVE-2026-27143)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
  • BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
  • BZ - 2456340 - CVE-2026-27144 golang: cmd/compile: no-op interface conversion bypasses overlap checking
  • BZ - 2456341 - CVE-2026-27140 cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names
  • BZ - 2456342 - CVE-2026-27143 golang: cmd/compile: possible memory corruption after bound check elimination
  • RHEL-169928 - Update Go to version 1.25.9+2 [rhel-10.1.z]

CVEs

  • CVE-2026-27140
  • CVE-2026-27143
  • CVE-2026-27144
  • CVE-2026-32280
  • CVE-2026-32282
  • CVE-2026-32283

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
golang-1.25.9-3.el10_1.src.rpm SHA-256: fa0f7d9e656c542827ff78c4e4cca396ea1069fc142527334a3b948ceb5a2c21
x86_64
go-toolset-1.25.9-3.el10_1.x86_64.rpm SHA-256: d6c793d14253a5e402a4348da22c36832a8355d8b236155ae5fe337d05510236
golang-1.25.9-3.el10_1.x86_64.rpm SHA-256: 1064f9005aa24d99e80db968fc6b5ea2248e9dc75793920844b3a5ae43320d3b
golang-bin-1.25.9-3.el10_1.x86_64.rpm SHA-256: c631253d09166fa9e13bbeaccb3ba30e777adb10b060717426055771ef138e09
golang-docs-1.25.9-3.el10_1.noarch.rpm SHA-256: c8e1de847d782aa46a0c62fec2adef291c7c621ce3e993efec690e4529e0a29a
golang-misc-1.25.9-3.el10_1.noarch.rpm SHA-256: 3ba104c811f66f53a45d2dff268337d99fbc4b9238887a92854f7191e84a5df0
golang-race-1.25.9-3.el10_1.x86_64.rpm SHA-256: dd7243ff5188c837a936bb3036d65a234a3c195949e691a912c2e9dd9c8bf0a3
golang-src-1.25.9-3.el10_1.noarch.rpm SHA-256: d11d60462f8add1e7eb7f236696065a72342759295317d441c973b71755d5950
golang-tests-1.25.9-3.el10_1.noarch.rpm SHA-256: 1f3bbd621a3f0b752e91c8720b003c5a7a2aa8e52874d4f9741f1170c850ecc7

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
golang-1.25.9-3.el10_1.src.rpm SHA-256: fa0f7d9e656c542827ff78c4e4cca396ea1069fc142527334a3b948ceb5a2c21
s390x
go-toolset-1.25.9-3.el10_1.s390x.rpm SHA-256: d77035709f557e5cfbcb25f1ee01329b925ae57bccc1097aaebee6c9df721c02
golang-1.25.9-3.el10_1.s390x.rpm SHA-256: b46afcbe2a72202824e2d795f13c07bb040c2aa0479bd96d83883f1d17952db3
golang-bin-1.25.9-3.el10_1.s390x.rpm SHA-256: 4126ea0492f619635ab2d47d6366f9c468f08ca0ae7d6e029c35e5b60b59feb4
golang-docs-1.25.9-3.el10_1.noarch.rpm SHA-256: c8e1de847d782aa46a0c62fec2adef291c7c621ce3e993efec690e4529e0a29a
golang-misc-1.25.9-3.el10_1.noarch.rpm SHA-256: 3ba104c811f66f53a45d2dff268337d99fbc4b9238887a92854f7191e84a5df0
golang-race-1.25.9-3.el10_1.s390x.rpm SHA-256: a08bb836ba9f55c3b9b8f4bcc2de0de474f362a1332d44a6dfea0ae649c114bd
golang-src-1.25.9-3.el10_1.noarch.rpm SHA-256: d11d60462f8add1e7eb7f236696065a72342759295317d441c973b71755d5950
golang-tests-1.25.9-3.el10_1.noarch.rpm SHA-256: 1f3bbd621a3f0b752e91c8720b003c5a7a2aa8e52874d4f9741f1170c850ecc7

Red Hat Enterprise Linux for Power, little endian 10

SRPM
golang-1.25.9-3.el10_1.src.rpm SHA-256: fa0f7d9e656c542827ff78c4e4cca396ea1069fc142527334a3b948ceb5a2c21
ppc64le
go-toolset-1.25.9-3.el10_1.ppc64le.rpm SHA-256: 419fec6e914012d7491922096daba076e293dba6f8410e24baca834eefe06317
golang-1.25.9-3.el10_1.ppc64le.rpm SHA-256: 80deca985ad5a4b643dbe97b405efbdaddbae8d5209695fd6508defd7440e101
golang-bin-1.25.9-3.el10_1.ppc64le.rpm SHA-256: d5d1fdf62b09047ce172059df71fa676494a9351f93b6b0e778d693f60deabf7
golang-docs-1.25.9-3.el10_1.noarch.rpm SHA-256: c8e1de847d782aa46a0c62fec2adef291c7c621ce3e993efec690e4529e0a29a
golang-misc-1.25.9-3.el10_1.noarch.rpm SHA-256: 3ba104c811f66f53a45d2dff268337d99fbc4b9238887a92854f7191e84a5df0
golang-race-1.25.9-3.el10_1.ppc64le.rpm SHA-256: b01c5124bc7baca33094003bfc560ca7e24e7a9e1bf54a9c5235a43413a91b85
golang-src-1.25.9-3.el10_1.noarch.rpm SHA-256: d11d60462f8add1e7eb7f236696065a72342759295317d441c973b71755d5950
golang-tests-1.25.9-3.el10_1.noarch.rpm SHA-256: 1f3bbd621a3f0b752e91c8720b003c5a7a2aa8e52874d4f9741f1170c850ecc7

Red Hat Enterprise Linux for ARM 64 10

SRPM
golang-1.25.9-3.el10_1.src.rpm SHA-256: fa0f7d9e656c542827ff78c4e4cca396ea1069fc142527334a3b948ceb5a2c21
aarch64
go-toolset-1.25.9-3.el10_1.aarch64.rpm SHA-256: 551d88fc3943fb732c5d4a9f436ee9a66428d6a5d4a3105ef4b55d4ed83f5c91
golang-1.25.9-3.el10_1.aarch64.rpm SHA-256: 8f9b5bc1550a2d56584edc78acedf7b564fe08f6c82a73d755c47484f4a240d6
golang-bin-1.25.9-3.el10_1.aarch64.rpm SHA-256: 41394e7764799bcc3c2016466caf6032e3ad49fb67594f4e7b856b4519a7b698
golang-docs-1.25.9-3.el10_1.noarch.rpm SHA-256: c8e1de847d782aa46a0c62fec2adef291c7c621ce3e993efec690e4529e0a29a
golang-misc-1.25.9-3.el10_1.noarch.rpm SHA-256: 3ba104c811f66f53a45d2dff268337d99fbc4b9238887a92854f7191e84a5df0
golang-race-1.25.9-3.el10_1.aarch64.rpm SHA-256: e8eb3dc29d98138bf2241ca21073703835ddd7b9143db9d1089723aceb7b1423
golang-src-1.25.9-3.el10_1.noarch.rpm SHA-256: d11d60462f8add1e7eb7f236696065a72342759295317d441c973b71755d5950
golang-tests-1.25.9-3.el10_1.noarch.rpm SHA-256: 1f3bbd621a3f0b752e91c8720b003c5a7a2aa8e52874d4f9741f1170c850ecc7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility