Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Description:
The updated packages fix security vulnerabilities:
mime: quadratic complexity in WordDecoder.DecodeHeader. (CVE-2026-42504)
net/textproto: arbitrary input are included in errors without any
escaping. (CVE-2026-42507)
crypto/x509: split candidate hostname only once. (CVE-2026-27145)
os: Root escape via symlink plus trailing slash. (CVE-2026-39822)
crypto/tls: Encrypted Client Hello privacy leak. (CVE-2026-42505)
- https://bugs.mageia.org/show_bug.cgi?id=35624
- https://www.openwall.com/lists/oss-security/2026/06/03/2
- https://www.openwall.com/lists/oss-security/2026/07/08/10
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/PHOAHESABWDZPEWFOMKYQVZYR2MQH3RA/
- https://www.cve.org/CVERecord?id=CVE-2026-42504
- https://www.cve.org/CVERecord?id=CVE-2026-42507
- https://www.cve.org/CVERecord?id=CVE-2026-27145
- https://www.cve.org/CVERecord?id=CVE-2026-39822
- https://www.cve.org/CVERecord?id=CVE-2026-42505
- 10/core/golang-1.25.12-1.mga10
- 9/core/golang-1.25.12-1.mga9
Publication date:20 Jul 2026
Get the latest Linux and open source security news straight to your inbox.