This update for go1.24 fixes the following issues:
This update ships go1.24rc2 (bsc#1236217).
* CVE-2024-45341: Properly check for IPv6 hosts in URIs (bsc#1236045)
* CVE-2024-45336: Persist header stripping across repeated redirects
(bsc#1236046)
* CVE-2025-22865: Avoid panic when parsing partial PKCS#1 private keys
(bsc#1236361)
* CVE-2024-45340: Restore netrc preferences for GOAUTH and fix domain lookup
(bsc#1236360)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP3 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-285=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-285=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-285=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP3
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-285=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-285=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-285=1
* SUSE Enterprise Storage 7.1
zypper in -t patch SUSE-Storage-7.1-2025-285=1
* openSUSE Leap 15.6
zypper in -t patch...
Read the Full Advisory* SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64)
* go1.24-race-1.24rc2-150000.1.3.1
* go1.24-1.24rc2-150000.1.3.1
* go1.24-doc-1.24rc2-150000.1.3.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* go1.24-race-1.24rc2-150000.1.3.1
* go1.24-1.24rc2-150000.1.3.1
* go1.24-doc-1.24rc2-150000.1.3.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* go1.24-race-1.24rc2-150000.1.3.1
* go1.24-1.24rc2-150000.1.3.1
* go1.24-doc-1.24rc2-150000.1.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64)
* go1.24-race-1.24rc2-150000.1.3.1
* go1.24-1.24rc2-150000.1.3.1
* go1.24-doc-1.24rc2-150000.1.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* go1.24-race-1.24rc2-150000.1.3.1
* go1.24-1.24rc2-150000.1.3.1
* go1.24-doc-1.24rc2-150000.1.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* go1.24-race-1.24rc2-150000.1.3.1
* go1.24-1.24rc2-150000.1.3.1
*...
Read the Full Advisory* bsc#1236045
* bsc#1236046
* bsc#1236217
* bsc#1236360
* bsc#1236361
## References:
* https://www.suse.com/security/cve/CVE-2024-45336.html
* https://www.suse.com/security/cve/CVE-2024-45340.html
* https://www.suse.com/security/cve/CVE-2024-45341.html
* https://www.suse.com/security/cve/CVE-2025-22865.html
* https://bugzilla.suse.com/show_bug.cgi?id=1236045
* https://bugzilla.suse.com/show_bug.cgi?id=1236046
* https://bugzilla.suse.com/show_bug.cgi?id=1236217
* https://bugzilla.suse.com/show_bug.cgi?id=1236360
* https://bugzilla.suse.com/show_bug.cgi?id=1236361
Get the latest Linux and open source security news straight to your inbox.