This update for go1.24-openssl fixes the following issues:
Update to version 1.24.12 (released 2026-01-15) (jsc#SLE-18320, bsc#1236217):
Security fixes:
* CVE-2025-47912: net/url: insufficient validation of bracketed IPv6 hostnames
(bsc#1251257).
* CVE-2025-58183: archive/tar: unbounded allocation when parsing GNU sparse
map (bsc#1251261).
* CVE-2025-58185: encoding/asn1: pre-allocating memory when parsing DER
payload can cause memory exhaustion (bsc#1251258).
* CVE-2025-58186: net/http: lack of limit when parsing cookies can cause
memory exhaustion (bsc#1251259).
* CVE-2025-58187: crypto/x509: quadratic complexity when checking name
constraints (bsc#1251254).
* CVE-2025-58188: crypto/x509: panic when validating certificates with DSA
public keys (bsc#1251260).
* CVE-2025-58189: crypto/tls: ALPN negotiation error contains attacker
controlled information (bsc#1251255).
* CVE-2025-61723: encoding/pem: quadratic complexity when parsing some...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-308=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-308=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-308=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-308=1 openSUSE-SLE-15.6-2026-308=1
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* go1.24-openssl-doc-1.24.12-150600.13.15.1
* go1.24-openssl-debuginfo-1.24.12-150600.13.15.1
* go1.24-openssl-1.24.12-150600.13.15.1
* go1.24-openssl-race-1.24.12-150600.13.15.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* go1.24-openssl-doc-1.24.12-150600.13.15.1
* go1.24-openssl-race-1.24.12-150600.13.15.1
* go1.24-openssl-1.24.12-150600.13.15.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* go1.24-openssl-doc-1.24.12-150600.13.15.1
* go1.24-openssl-race-1.24.12-150600.13.15.1
* go1.24-openssl-1.24.12-150600.13.15.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* go1.24-openssl-doc-1.24.12-150600.13.15.1
* go1.24-openssl-debuginfo-1.24.12-150600.13.15.1
* go1.24-openssl-1.24.12-150600.13.15.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* go1.24-openssl-race-1.24.12-150600.13.15.1
* bsc#1236217
* bsc#1245878
* bsc#1247816
* bsc#1248082
* bsc#1249985
* bsc#1251253
* bsc#1251254
* bsc#1251255
* bsc#1251256
* bsc#1251257
* bsc#1251258
* bsc#1251259
* bsc#1251260
* bsc#1251261
* bsc#1251262
* bsc#1254430
* bsc#1254431
* bsc#1256816
* bsc#1256817
* bsc#1256818
* bsc#1256819
* bsc#1256820
* bsc#1256821
* jsc#SLE-18320
## References:
* https://www.suse.com/security/cve/CVE-2025-47912.html
* https://www.suse.com/security/cve/CVE-2025-58183.html
* https://www.suse.com/security/cve/CVE-2025-58185.html
* https://www.suse.com/security/cve/CVE-2025-58186.html
* https://www.suse.com/security/cve/CVE-2025-58187.html
* https://www.suse.com/security/cve/CVE-2025-58188.html
* https://www.suse.com/security/cve/CVE-2025-58189.html
* https://www.suse.com/security/cve/CVE-2025-61723.html
* https://www.suse.com/security/cve/CVE-2025-61724.html
* https://www.suse.com/security/cve/CVE-2025-61725.html
* https://www.suse.com/security/cve/CVE-2025-61726.html
* https://www.suse.com/security/cve/CVE-2025-61727.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.