This security update of go1.24-openssl fixes the following issues:
Update to version 1.24.6 cut from the go1.24-fips-release branch at the revision
tagged go1.24.6-1-openssl-fips. Refs jsc#SLE-18320
* Fix HKDF-Extract The latest OpenSSL in c9s/c10s requires nil salt to be
passed as a hash length buffer of zeros.
go1.24.6 (released 2025-08-06) includes security fixes to the database/sql and
os/exec packages, as well as bug fixes to the runtime. ( boo#1236217 go1.24
release tracking)
CVE-2025-47906 CVE-2025-47907:
* go#74804 go#74466 boo#1247719 security: fix CVE-2025-47906 os/exec: LookPath
bug: incorrect expansion of "", "." and ".." in some PATH configurations
* go#74833 go#74831 boo#1247720 security: fix CVE-2025-47907 database/sql:
incorrect results returned from Rows.Scan
* go#73800 runtime: RSS seems to have increased in Go 1.24 while the runtime
accounting has not
* go#74416 runtime: use-after-free of allpSnapshot in findRunnable
* go#74694...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Development Tools Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-3158=1
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-3158=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2025-3158=1 openSUSE-SLE-15.6-2025-3158=1
* Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64)
* go1.24-openssl-race-1.24.6-150600.13.9.1
* go1.24-openssl-doc-1.24.6-150600.13.9.1
* go1.24-openssl-1.24.6-150600.13.9.1
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* go1.24-openssl-race-1.24.6-150600.13.9.1
* go1.24-openssl-debuginfo-1.24.6-150600.13.9.1
* go1.24-openssl-doc-1.24.6-150600.13.9.1
* go1.24-openssl-1.24.6-150600.13.9.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* go1.24-openssl-debuginfo-1.24.6-150600.13.9.1
* go1.24-openssl-doc-1.24.6-150600.13.9.1
* go1.24-openssl-1.24.6-150600.13.9.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* go1.24-openssl-race-1.24.6-150600.13.9.1
* bsc#1236217
* bsc#1244156
* bsc#1244157
* bsc#1244158
* bsc#1246118
* bsc#1247719
* bsc#1247720
* jsc#SLE-18320
## References:
* https://www.suse.com/security/cve/CVE-2025-0913.html
* https://www.suse.com/security/cve/CVE-2025-22874.html
* https://www.suse.com/security/cve/CVE-2025-4673.html
* https://www.suse.com/security/cve/CVE-2025-4674.html
* https://www.suse.com/security/cve/CVE-2025-47906.html
* https://www.suse.com/security/cve/CVE-2025-47907.html
* https://bugzilla.suse.com/show_bug.cgi?id=1236217
* https://bugzilla.suse.com/show_bug.cgi?id=1244156
* https://bugzilla.suse.com/show_bug.cgi?id=1244157
* https://bugzilla.suse.com/show_bug.cgi?id=1244158
* https://bugzilla.suse.com/show_bug.cgi?id=1246118
* https://bugzilla.suse.com/show_bug.cgi?id=1247719
* https://bugzilla.suse.com/show_bug.cgi?id=1247720
* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FSLE-18320&page_caps=&user_role=
Get the latest Linux and open source security news straight to your inbox.