Linuxsecurity
SUSE Releases Security Updates for Go1.25 and Go1.26 Addressing Multiple CVEs
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SUSE has released security updates for Go versions 1.25 and 1.26, addressing three critical vulnerabilities identified as CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507. These vulnerabilities affect the crypto/x509, mime, and net/textproto packages, posing risks such as arbitrary input handling and quadratic complexity issues. The vulnerabilities were published on June 2, 2026, with the first public proof of concept for CVE-2026-27145 appearing on June 3, 2026. The updates are rated as moderate, and users are advised to apply the patches promptly to mitigate potential exploitation. The vulnerabilities could allow attackers to manipulate data processing and potentially execute arbitrary code. Both updates were released on June 9, 2026, and are crucial for maintaining the security of applications utilizing these Go versions.
Key Points: • SUSE issued updates for Go1.25 and Go1.26 to address three CVEs. • CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 were published on June 2, 2026. • The updates are rated as moderate, and users are urged to apply them to prevent exploitation.