SUSE Releases Security Updates for Go1.25 and Go1.26 Addressing Multiple CVEs

SUSE Releases Security Updates for Go1.25 and Go1.26 Addressing Multiple CVEs

First seen 10 Jun 2026, 15:02 UTC Linuxsecurity 96% similarity 57.8

Article Content

Browse articles
ThreatCluster

SUSE has released security updates for Go versions 1.25 and 1.26, addressing three critical vulnerabilities identified as CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507. These vulnerabilities affect the crypto/x509, mime, and net/textproto packages, posing risks such as arbitrary input handling and quadratic complexity issues. The vulnerabilities were published on June 2, 2026, with the first public proof of concept for CVE-2026-27145 appearing on June 3, 2026. The updates are rated as moderate, and users are advised to apply the patches promptly to mitigate potential exploitation. The vulnerabilities could allow attackers to manipulate data processing and potentially execute arbitrary code. Both updates were released on June 9, 2026, and are crucial for maintaining the security of applications utilizing these Go versions.

Key Points: • SUSE issued updates for Go1.25 and Go1.26 to address three CVEs. • CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 were published on June 2, 2026. • The updates are rated as moderate, and users are urged to apply them to prevent exploitation.

ThreatCluster AI

Timeline

2026-06-02
CVE-2026-42507 published
CVE-2026-42507 was disclosed, detailing vulnerabilities in Go's net/textproto package.
Linuxsecurity
2026-06-02
CVE-2026-42504 published
CVE-2026-42504 was disclosed, highlighting issues in Go's mime package.
Linuxsecurity
2026-06-02
CVE-2026-27145 published
CVE-2026-27145 was published, affecting Go's crypto/x509 package, with a PoC released on June 3.
Linuxsecurity
2026-06-03
First public PoC for CVE-2026-27145
A proof of concept for CVE-2026-27145 was made public, demonstrating the vulnerability.
Linuxsecurity
2026-06-09
SUSE releases updates for Go1.25 and Go1.26
SUSE released security updates for Go1.25 and Go1.26 addressing the identified vulnerabilities.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story