Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5941 - Security Advisory
Issued:
2026-03-26
Updated:
2026-03-26

RHSA-2026:5941 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: golang security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for golang is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The golang packages provide the Go programming language compiler.

Security Fix(es):

  • cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive (CVE-2025-61731)
  • net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2434433 - CVE-2025-61731 cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive
  • BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url

CVEs

  • CVE-2025-61731
  • CVE-2026-25679

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
golang-1.25.8-1.el10_1.src.rpm SHA-256: 340bc3ce30dd3803277e4bca7e913344cf73a977f2efbcdbd7c3e63bbeba7750
x86_64
go-toolset-1.25.8-1.el10_1.x86_64.rpm SHA-256: 8596019fba44640c973194afe2040521f44b1f4f109e1dc34b9221007e5f6b5e
golang-1.25.8-1.el10_1.x86_64.rpm SHA-256: ab709e3342a410a7276ad681a862534b29b015dd7afb8a14ac85b3dce6f03d34
golang-bin-1.25.8-1.el10_1.x86_64.rpm SHA-256: ad00cbdd982055b1d9d9aeaa18036fa7b77d2a4b32794c7dcd52eed6a292fabf
golang-docs-1.25.8-1.el10_1.noarch.rpm SHA-256: 52641d2094dd223f6fa8db9d001fee28c3ca93938ff955dbcd32d541678c6d3d
golang-misc-1.25.8-1.el10_1.noarch.rpm SHA-256: 2d3d911772ecf4ff55099c975ea2f36f3d3a6ebdbf03d05cc431e6646b723f09
golang-race-1.25.8-1.el10_1.x86_64.rpm SHA-256: 468e46495af71fb84cce7033a2f97f1729e85e5015a81c1366aee9660044f585
golang-src-1.25.8-1.el10_1.noarch.rpm SHA-256: 1bccae19005032a5cb988dde0e8da5facad2a47e3fa8c3a47d2f55c0b18b244f
golang-tests-1.25.8-1.el10_1.noarch.rpm SHA-256: 5d1bfa6486ecbf8b9df7cef587faa130edd48d084e4c1c071f2e3103257ec0ee

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
golang-1.25.8-1.el10_1.src.rpm SHA-256: 340bc3ce30dd3803277e4bca7e913344cf73a977f2efbcdbd7c3e63bbeba7750
s390x
go-toolset-1.25.8-1.el10_1.s390x.rpm SHA-256: 1f43bdd8a7189de030dcf1b44d4f1fb1612685a52d2ef8a33642e2e1e4966eed
golang-1.25.8-1.el10_1.s390x.rpm SHA-256: b151bc79fbc6fced9b9754732d5c278fc79e03da21058262ae60a6d06ac30bb6
golang-bin-1.25.8-1.el10_1.s390x.rpm SHA-256: 4785bd3cd2f7971577b4fd44243c00c6adb8d729287a19270a21da94eeb6f8b1
golang-docs-1.25.8-1.el10_1.noarch.rpm SHA-256: 52641d2094dd223f6fa8db9d001fee28c3ca93938ff955dbcd32d541678c6d3d
golang-misc-1.25.8-1.el10_1.noarch.rpm SHA-256: 2d3d911772ecf4ff55099c975ea2f36f3d3a6ebdbf03d05cc431e6646b723f09
golang-race-1.25.8-1.el10_1.s390x.rpm SHA-256: 9910f71a31e0e242a6ed455899f2f1e89b7afef246b50c8b571c884e5e999940
golang-src-1.25.8-1.el10_1.noarch.rpm SHA-256: 1bccae19005032a5cb988dde0e8da5facad2a47e3fa8c3a47d2f55c0b18b244f
golang-tests-1.25.8-1.el10_1.noarch.rpm SHA-256: 5d1bfa6486ecbf8b9df7cef587faa130edd48d084e4c1c071f2e3103257ec0ee

Red Hat Enterprise Linux for Power, little endian 10

SRPM
golang-1.25.8-1.el10_1.src.rpm SHA-256: 340bc3ce30dd3803277e4bca7e913344cf73a977f2efbcdbd7c3e63bbeba7750
ppc64le
go-toolset-1.25.8-1.el10_1.ppc64le.rpm SHA-256: 8778892363c43088ac45b33bff6c441de91ce4ce7348cc7ae253e8b12e010784
golang-1.25.8-1.el10_1.ppc64le.rpm SHA-256: a0dc1ab060d831e99b717cf9a544c9f5781d6650023c1a2fc5a1070f1bfb7016
golang-bin-1.25.8-1.el10_1.ppc64le.rpm SHA-256: f5fbd55fa0f489548a7914513bebcc6de8ffb0fe65708644f4ff2873963072b4
golang-docs-1.25.8-1.el10_1.noarch.rpm SHA-256: 52641d2094dd223f6fa8db9d001fee28c3ca93938ff955dbcd32d541678c6d3d
golang-misc-1.25.8-1.el10_1.noarch.rpm SHA-256: 2d3d911772ecf4ff55099c975ea2f36f3d3a6ebdbf03d05cc431e6646b723f09
golang-race-1.25.8-1.el10_1.ppc64le.rpm SHA-256: 6cc2adda1371c8bb9b020eb5f5b9754dc9ba48a4a59eac79c6725b3b04f6e989
golang-src-1.25.8-1.el10_1.noarch.rpm SHA-256: 1bccae19005032a5cb988dde0e8da5facad2a47e3fa8c3a47d2f55c0b18b244f
golang-tests-1.25.8-1.el10_1.noarch.rpm SHA-256: 5d1bfa6486ecbf8b9df7cef587faa130edd48d084e4c1c071f2e3103257ec0ee

Red Hat Enterprise Linux for ARM 64 10

SRPM
golang-1.25.8-1.el10_1.src.rpm SHA-256: 340bc3ce30dd3803277e4bca7e913344cf73a977f2efbcdbd7c3e63bbeba7750
aarch64
go-toolset-1.25.8-1.el10_1.aarch64.rpm SHA-256: f363e355322611dd62b87903302e4b3a90dea000891dbadee403825b04a562e2
golang-1.25.8-1.el10_1.aarch64.rpm SHA-256: 7f6ae3cf3b6bdd4e797fb922070e11cc902acc9f18845f4423a3b2b2e5cf29f8
golang-bin-1.25.8-1.el10_1.aarch64.rpm SHA-256: 5331947d7266865fd385814d7a2c86a74de8e07fe95559b05b266c4a28564275
golang-docs-1.25.8-1.el10_1.noarch.rpm SHA-256: 52641d2094dd223f6fa8db9d001fee28c3ca93938ff955dbcd32d541678c6d3d
golang-misc-1.25.8-1.el10_1.noarch.rpm SHA-256: 2d3d911772ecf4ff55099c975ea2f36f3d3a6ebdbf03d05cc431e6646b723f09
golang-race-1.25.8-1.el10_1.aarch64.rpm SHA-256: 12bc19fe7e440a01de76295dbd49fc3fc0a3d7490d5fab53b4a7daac3b07c098
golang-src-1.25.8-1.el10_1.noarch.rpm SHA-256: 1bccae19005032a5cb988dde0e8da5facad2a47e3fa8c3a47d2f55c0b18b244f
golang-tests-1.25.8-1.el10_1.noarch.rpm SHA-256: 5d1bfa6486ecbf8b9df7cef587faa130edd48d084e4c1c071f2e3103257ec0ee

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility