Skip to content
Denial of Service Vulnerability in Fedora's golang-x-perf Package

Denial of Service Vulnerability in Fedora's golang-x-perf Package

First seen 14 Sep 2026, 06:41 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 08:12 UTC
  • CVE-2026-27145 allows DoS via excessive DNS SAN processing.
  • Affected systems include Fedora 43 and 45 using golang-x-perf.
  • Patching is critical to prevent potential service disruptions.

A Denial of Service (DoS) vulnerability identified as CVE-2026-27145 affects the golang-x-perf package in Fedora 43 and 45. The flaw allows excessive processing of DNS Subject Alternative Name (SAN) entries, potentially leading to service disruptions. This vulnerability impacts systems running Fedora 43 and 45 that utilize the golang-x-perf package. The issue was publicly disclosed on June 2, 2026, with a proof-of-concept (PoC) available shortly after. Fedora users are urged to apply the latest updates to mitigate the risk. The vulnerability is categorized under the 'fedora-all' advisory. The update can be installed via the 'dnf' package manager. Administrators should prioritize patching to ensure system security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-02
CVE-2026-27145 published
The vulnerability affecting golang-x-perf was publicly disclosed, allowing for potential DoS attacks.
Linuxsecurity
2026-06-03
First public PoC released
A proof-of-concept for exploiting CVE-2026-27145 was made available, demonstrating the vulnerability's impact.
Linuxsecurity
2026-09-04
Updates released for Fedora 43 and 45
Fedora released updates to address the DoS vulnerability in the golang-x-perf package, urging users to apply them immediately.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-27145 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed