Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

openSUSE go1.25-openssl Important Security Issues 2026-3151-1

opensuse
Calendar Grey July 21, 2026
Scroller Opensuse
An update for openSUSE addresses important issues in go1.25-openssl with critical fixes included.
An update that solves eight vulnerabilities, contains two features and has three security fixes can now be installed.

Description

This update for go1.25-openssl fixes the following issues

* Update to version go1.25.12 (bsc#1244485).

* CVE-2026-25679: net/url: reject IPv6 literal not at start of host

(bsc#1259264).

* CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268).

* CVE-2026-27142: html/template: URLs in meta content attribute actions are

not escaped (bsc#1259265).

* CVE-2026-27145: crypto/x509: split candidate hostname only once

(bsc#1267450).

* CVE-2026-39822: os: Root escape via symlink plus trailing slash

(bsc#1271014).

* CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader

(bsc#1267442).

* CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello

(bsc#1271015).

* CVE-2026-42507: net/textproto: arbitrary input are included in errors

without any escaping (bsc#1267444).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3151=1

* Development Tools Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3151=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-3151=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3151=1

Package List

* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)

* go1.25-openssl-1.25.12-150600.13.21.1

* go1.25-openssl-debuginfo-1.25.12-150600.13.21.1

* go1.25-openssl-doc-1.25.12-150600.13.21.1

* go1.25-openssl-race-1.25.12-150600.13.21.1

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* go1.25-openssl-1.25.12-150600.13.21.1

* go1.25-openssl-debuginfo-1.25.12-150600.13.21.1

* go1.25-openssl-doc-1.25.12-150600.13.21.1

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)

* go1.25-openssl-race-1.25.12-150600.13.21.1

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)

* go1.25-openssl-1.25.12-150600.13.21.1

* go1.25-openssl-debuginfo-1.25.12-150600.13.21.1

* go1.25-openssl-doc-1.25.12-150600.13.21.1

* go1.25-openssl-race-1.25.12-150600.13.21.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)

* go1.25-openssl-1.25.12-150600.13.21.1

* go1.25-openssl-debuginfo-1.25.12-150600.13.21.1

* go1.25-openssl-doc-1.25.12-150600.13.21.1

*...

Read the Full Advisory

References

* bsc#1244485

* bsc#1245878

* bsc#1259264

* bsc#1259265

* bsc#1259268

* bsc#1264394

* bsc#1267442

* bsc#1267444

* bsc#1267450

* bsc#1271014

* bsc#1271015

* jsc#PED-1962

* jsc#SLE-18320

## References:

* https://www.suse.com/security/cve/CVE-2026-25679.html

* https://www.suse.com/security/cve/CVE-2026-27139.html

* https://www.suse.com/security/cve/CVE-2026-27142.html

* https://www.suse.com/security/cve/CVE-2026-27145.html

* https://www.suse.com/security/cve/CVE-2026-39822.html

* https://www.suse.com/security/cve/CVE-2026-42504.html

* https://www.suse.com/security/cve/CVE-2026-42505.html

* https://www.suse.com/security/cve/CVE-2026-42507.html

* https://bugzilla.suse.com/show_bug.cgi?id=1244485

* https://bugzilla.suse.com/show_bug.cgi?id=1245878

* https://bugzilla.suse.com/show_bug.cgi?id=1259264

* https://bugzilla.suse.com/show_bug.cgi?id=1259265

* https://bugzilla.suse.com/show_bug.cgi?id=1259268

* https://bugzilla.suse.com/show_bug.cgi?id=1264394

* https://bugzilla.suse.com/show_bug.cgi?id=1267442

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3151-1
Release Date: 2026-07-21T12:48:54Z
Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.