Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:47712 - Security Advisory
Issued:
2026-07-29
Updated:
2026-07-29

RHSA-2026:47712 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: golang security, bug fix, and enhancement update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for golang is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The golang packages provide the Go programming language compiler.

Security Fix(es):

  • crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)
  • crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
  • golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
  • crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
  • crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
  • golang: cmd/compile: no-op interface conversion bypasses overlap checking (CVE-2026-27144)
  • golang: cmd/compile: possible memory corruption after bound check elimination (CVE-2026-27143)

Bug Fix(es) and Enhancement(s):

  • Update Go to version 1.25.9+2 [rhel-9.4.z] (JIRA:RHEL-178854)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x

Fixes

  • BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption
  • BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
  • BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
  • BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
  • BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
  • BZ - 2456340 - CVE-2026-27144 golang: cmd/compile: no-op interface conversion bypasses overlap checking
  • BZ - 2456342 - CVE-2026-27143 golang: cmd/compile: possible memory corruption after bound check elimination
  • RHEL-178854 - Update Go to version 1.25.9+2 [rhel-9.4.z]

CVEs

  • CVE-2025-22874
  • CVE-2025-68121
  • CVE-2026-27143
  • CVE-2026-27144
  • CVE-2026-32280
  • CVE-2026-32281
  • CVE-2026-32282
  • CVE-2026-32283

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
x86_64
go-toolset-1.25.9-1.el9_4.x86_64.rpm SHA-256: 5d443014b6562923ae8d0fb5ef49a910e095a71af713e61e7c8e3d3599e4b21c
golang-1.25.9-1.el9_4.x86_64.rpm SHA-256: 3971bd8bed5305b7ed26a6abad280480555ee0b6ec8f9855fba1f434c9765380
golang-bin-1.25.9-1.el9_4.x86_64.rpm SHA-256: d88336cbdbd3bc35b4843c13f016368ffdff719ee018c34d5a76799211fd9693
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
ppc64le
go-toolset-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 975a1cbfc8990d36637bea3fde47af3e5a7f2e20d9c774f5dbc4224771d5677f
golang-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 52ae595c56290b0a4cc5ba17e2ee943363777ef172836943f29b1d41390524d4
golang-bin-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 4e6f1613496a5380cc3c8fe9f93003b16f3d10b943c0b4878f2451b4fb461182
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
x86_64
go-toolset-1.25.9-1.el9_4.x86_64.rpm SHA-256: 5d443014b6562923ae8d0fb5ef49a910e095a71af713e61e7c8e3d3599e4b21c
golang-1.25.9-1.el9_4.x86_64.rpm SHA-256: 3971bd8bed5305b7ed26a6abad280480555ee0b6ec8f9855fba1f434c9765380
golang-bin-1.25.9-1.el9_4.x86_64.rpm SHA-256: d88336cbdbd3bc35b4843c13f016368ffdff719ee018c34d5a76799211fd9693
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
aarch64
go-toolset-1.25.9-1.el9_4.aarch64.rpm SHA-256: cae72c703811c94753afc08f355cf7f5b6b4247c5817a72e245247824180b796
golang-1.25.9-1.el9_4.aarch64.rpm SHA-256: f87e4dd8de0d7d3f8998cb8c358bcd6315cd41a0f8cf863c694f7a3345d99f06
golang-bin-1.25.9-1.el9_4.aarch64.rpm SHA-256: 62b04c10cd26a6cafe2deccf08d99b1edb265b6c85ac49325dbac2304a23c8a7
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
s390x
go-toolset-1.25.9-1.el9_4.s390x.rpm SHA-256: 41c5cffdd9e65d7a316df167ff51047115e8acfe284a6aef130bee5c7d796cd2
golang-1.25.9-1.el9_4.s390x.rpm SHA-256: 1a9b331a3228d29268754bf4edefd00c8d3cd6839f17054b6da3191f62780a0b
golang-bin-1.25.9-1.el9_4.s390x.rpm SHA-256: dbea9f29d4d714186988fce91273acfc6070aa430a331235646b9d32466d1482
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
x86_64
go-toolset-1.25.9-1.el9_4.x86_64.rpm SHA-256: 5d443014b6562923ae8d0fb5ef49a910e095a71af713e61e7c8e3d3599e4b21c
golang-1.25.9-1.el9_4.x86_64.rpm SHA-256: 3971bd8bed5305b7ed26a6abad280480555ee0b6ec8f9855fba1f434c9765380
golang-bin-1.25.9-1.el9_4.x86_64.rpm SHA-256: d88336cbdbd3bc35b4843c13f016368ffdff719ee018c34d5a76799211fd9693
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
aarch64
go-toolset-1.25.9-1.el9_4.aarch64.rpm SHA-256: cae72c703811c94753afc08f355cf7f5b6b4247c5817a72e245247824180b796
golang-1.25.9-1.el9_4.aarch64.rpm SHA-256: f87e4dd8de0d7d3f8998cb8c358bcd6315cd41a0f8cf863c694f7a3345d99f06
golang-bin-1.25.9-1.el9_4.aarch64.rpm SHA-256: 62b04c10cd26a6cafe2deccf08d99b1edb265b6c85ac49325dbac2304a23c8a7
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
ppc64le
go-toolset-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 975a1cbfc8990d36637bea3fde47af3e5a7f2e20d9c774f5dbc4224771d5677f
golang-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 52ae595c56290b0a4cc5ba17e2ee943363777ef172836943f29b1d41390524d4
golang-bin-1.25.9-1.el9_4.ppc64le.rpm SHA-256: 4e6f1613496a5380cc3c8fe9f93003b16f3d10b943c0b4878f2451b4fb461182
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4

SRPM
golang-1.25.9-1.el9_4.src.rpm SHA-256: 822c0f3bff0c4e16cb7ccfa1d94fe6c169d976ffc290aec7516ae0c1ff258b7e
s390x
go-toolset-1.25.9-1.el9_4.s390x.rpm SHA-256: 41c5cffdd9e65d7a316df167ff51047115e8acfe284a6aef130bee5c7d796cd2
golang-1.25.9-1.el9_4.s390x.rpm SHA-256: 1a9b331a3228d29268754bf4edefd00c8d3cd6839f17054b6da3191f62780a0b
golang-bin-1.25.9-1.el9_4.s390x.rpm SHA-256: dbea9f29d4d714186988fce91273acfc6070aa430a331235646b9d32466d1482
golang-docs-1.25.9-1.el9_4.noarch.rpm SHA-256: fdcad0360b67203e464519db424ba9bd217a3aadeb6aab80aa462f8215df80b9
golang-misc-1.25.9-1.el9_4.noarch.rpm SHA-256: 68d10d7cdecf132198ed346ee788359a4da960a3b01d534d6b6c65761e7476a3
golang-src-1.25.9-1.el9_4.noarch.rpm SHA-256: a8658968dc06e3fbf4c639e24da7c690d4b0f2cdfda13fb6d1feeff44af79a1e
golang-tests-1.25.9-1.el9_4.noarch.rpm SHA-256: 962cd2ea18f377015b52a3148548238d9e1b858c9d8713de296b250003c87c85

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility