Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:10219 - Security Advisory
Issued:
2026-04-23
Updated:
2026-04-23

RHSA-2026:10219 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: golang security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for golang is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The golang packages provide the Go programming language compiler.

Security Fix(es):

  • golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
  • crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
  • crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
  • golang: cmd/compile: no-op interface conversion bypasses overlap checking (CVE-2026-27144)
  • cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names (CVE-2026-27140)
  • golang: cmd/compile: possible memory corruption after bound check elimination (CVE-2026-27143)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
  • BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
  • BZ - 2456340 - CVE-2026-27144 golang: cmd/compile: no-op interface conversion bypasses overlap checking
  • BZ - 2456341 - CVE-2026-27140 cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names
  • BZ - 2456342 - CVE-2026-27143 golang: cmd/compile: possible memory corruption after bound check elimination
  • RHEL-169931 - Update Go to version 1.25.9+2 [rhel-9.7]

CVEs

  • CVE-2026-27140
  • CVE-2026-27143
  • CVE-2026-27144
  • CVE-2026-32280
  • CVE-2026-32282
  • CVE-2026-32283

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
golang-1.25.9-1.el9_7.src.rpm SHA-256: 4d6a5c499c6c85326162d96c7d644c5c58f9ab3b972ccd92114eafe42a2fa805
x86_64
go-toolset-1.25.9-1.el9_7.x86_64.rpm SHA-256: f8c1624d9b78727cd6bedb3c73e72ad090ef7dd17016843ac31affa97fc7a6d7
golang-1.25.9-1.el9_7.x86_64.rpm SHA-256: 938b978911649aae551717cb758e4c0006e36595c92bb45ddc6bd232e401031d
golang-bin-1.25.9-1.el9_7.x86_64.rpm SHA-256: 58f1b0a6b1094cb77acf2aa6b0244459e6ac719709a385200e2f0dd7538af916
golang-docs-1.25.9-1.el9_7.noarch.rpm SHA-256: d38dd2b52bc51417b0caac5aaafb7e8ee9cfa8d557c86d60c93eaafe2bbf893d
golang-misc-1.25.9-1.el9_7.noarch.rpm SHA-256: fbcfec989142731e08323296c3d356e02b699015b2e0e57f6f11345078f08b91
golang-race-1.25.9-1.el9_7.x86_64.rpm SHA-256: 6597e9bf92453bb0ee9c10b3e43ecc460a218b7e88f650653679d2ed429c2f14
golang-src-1.25.9-1.el9_7.noarch.rpm SHA-256: d0c2c14d3314efc5aa2754065eacadc6ed19df654f53f3b460a50e321e58ba93
golang-tests-1.25.9-1.el9_7.noarch.rpm SHA-256: a9a69d964a437252ef4950c8a474635be3a6b96b0f0cc57dc5f9cfb2d1af2337

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
golang-1.25.9-1.el9_7.src.rpm SHA-256: 4d6a5c499c6c85326162d96c7d644c5c58f9ab3b972ccd92114eafe42a2fa805
s390x
go-toolset-1.25.9-1.el9_7.s390x.rpm SHA-256: d4b84dac9b80bafe183c0e2859ee75ed7b2768eda1773d76915f7bc2436f7098
golang-1.25.9-1.el9_7.s390x.rpm SHA-256: d26f372775197f05768f6d67ca4f0d705e1dd81b06c5dc2da9417332957c4a4e
golang-bin-1.25.9-1.el9_7.s390x.rpm SHA-256: bf4577c10b03fc033d707fc73e9d1da3e79e8a3ac9da1d72c2fba889e470a631
golang-docs-1.25.9-1.el9_7.noarch.rpm SHA-256: d38dd2b52bc51417b0caac5aaafb7e8ee9cfa8d557c86d60c93eaafe2bbf893d
golang-misc-1.25.9-1.el9_7.noarch.rpm SHA-256: fbcfec989142731e08323296c3d356e02b699015b2e0e57f6f11345078f08b91
golang-race-1.25.9-1.el9_7.s390x.rpm SHA-256: a7c6c27dcd667ebd1f7043130da527be9694e2dc2aa65bb1c1a28094844ede24
golang-src-1.25.9-1.el9_7.noarch.rpm SHA-256: d0c2c14d3314efc5aa2754065eacadc6ed19df654f53f3b460a50e321e58ba93
golang-tests-1.25.9-1.el9_7.noarch.rpm SHA-256: a9a69d964a437252ef4950c8a474635be3a6b96b0f0cc57dc5f9cfb2d1af2337

Red Hat Enterprise Linux for Power, little endian 9

SRPM
golang-1.25.9-1.el9_7.src.rpm SHA-256: 4d6a5c499c6c85326162d96c7d644c5c58f9ab3b972ccd92114eafe42a2fa805
ppc64le
go-toolset-1.25.9-1.el9_7.ppc64le.rpm SHA-256: c32760c256cddb39c00a0e5ba19db394eb97601de4ab8bcb498ca4360bf60ce3
golang-1.25.9-1.el9_7.ppc64le.rpm SHA-256: 2aaea61e0786b7b5b949c8de6b9870fcb8f41785a60e61f2f060b4ae9fcbd38f
golang-bin-1.25.9-1.el9_7.ppc64le.rpm SHA-256: b1ba864fd4234beb0609e4b43f2537adbcc025b46ea2be3f969650633a45869d
golang-docs-1.25.9-1.el9_7.noarch.rpm SHA-256: d38dd2b52bc51417b0caac5aaafb7e8ee9cfa8d557c86d60c93eaafe2bbf893d
golang-misc-1.25.9-1.el9_7.noarch.rpm SHA-256: fbcfec989142731e08323296c3d356e02b699015b2e0e57f6f11345078f08b91
golang-race-1.25.9-1.el9_7.ppc64le.rpm SHA-256: 57820f70b0d02a155a6b50fbace895753b5cebfbecf15f350d8d0ac39de6ef99
golang-src-1.25.9-1.el9_7.noarch.rpm SHA-256: d0c2c14d3314efc5aa2754065eacadc6ed19df654f53f3b460a50e321e58ba93
golang-tests-1.25.9-1.el9_7.noarch.rpm SHA-256: a9a69d964a437252ef4950c8a474635be3a6b96b0f0cc57dc5f9cfb2d1af2337

Red Hat Enterprise Linux for ARM 64 9

SRPM
golang-1.25.9-1.el9_7.src.rpm SHA-256: 4d6a5c499c6c85326162d96c7d644c5c58f9ab3b972ccd92114eafe42a2fa805
aarch64
go-toolset-1.25.9-1.el9_7.aarch64.rpm SHA-256: c1d223397ccf2a38d4ed8740c18961bf30986767b756be27b71212aea547a0bd
golang-1.25.9-1.el9_7.aarch64.rpm SHA-256: 6f16a5a8bda9fd4fc603e028014d07c5cdcd780b90f21bc4442381597db1ef54
golang-bin-1.25.9-1.el9_7.aarch64.rpm SHA-256: fe24fd02eb1a992d7f9fd2235ab73bffe153a7ea1827633c3ec80b5715405923
golang-docs-1.25.9-1.el9_7.noarch.rpm SHA-256: d38dd2b52bc51417b0caac5aaafb7e8ee9cfa8d557c86d60c93eaafe2bbf893d
golang-misc-1.25.9-1.el9_7.noarch.rpm SHA-256: fbcfec989142731e08323296c3d356e02b699015b2e0e57f6f11345078f08b91
golang-race-1.25.9-1.el9_7.aarch64.rpm SHA-256: b36ae854362c41e1ead021d6a6a990139231ab56c65d31d773117b46beea731f
golang-src-1.25.9-1.el9_7.noarch.rpm SHA-256: d0c2c14d3314efc5aa2754065eacadc6ed19df654f53f3b460a50e321e58ba93
golang-tests-1.25.9-1.el9_7.noarch.rpm SHA-256: a9a69d964a437252ef4950c8a474635be3a6b96b0f0cc57dc5f9cfb2d1af2337

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility