This update for go1.23-openssl fixes the following issues:
Update to version 1.23.12 cut from the go1.23-fips-release branch at the
revision tagged go1.23.12-1-openssl-fips. ( jsc#SLE-18320)
* Rebase to 1.23.12
* Fix HKDF-Extract The latest OpenSSL in c9s/c10s requires nil salt to be
passed as a hash length buffer of zeros.
Packaging improvements:
* Update go_bootstrap_version to go1.21 from go1.20 to shorten the bootstrap
chain. go1.21 can optionally be bootstrapped with gccgo and serve as the
inital version of go1.x.
* Refs boo#1247816 bootstrap go1.21 with gccgo
go1.23.12 (released 2025-08-06) includes security fixes to the database/sql and
os/exec packages, as well as bug fixes to the runtime.
CVE-2025-47906 CVE-2025-47907: * go#74803 go#74466 boo#1247719 security: fix
CVE-2025-47906 os/exec: LookPath bug: incorrect expansion of "", "." and ".." in
some PATH configurations * go#74832 go#74831 boo#1247720 security: fix
CVE-2025-47907 database/sql:...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2025-3159=1 openSUSE-SLE-15.6-2025-3159=1
* Development Tools Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-3159=1
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-3159=1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* go1.23-openssl-1.23.12-150600.13.9.1
* go1.23-openssl-doc-1.23.12-150600.13.9.1
* go1.23-openssl-debuginfo-1.23.12-150600.13.9.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* go1.23-openssl-race-1.23.12-150600.13.9.1
* Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64)
* go1.23-openssl-1.23.12-150600.13.9.1
* go1.23-openssl-doc-1.23.12-150600.13.9.1
* go1.23-openssl-race-1.23.12-150600.13.9.1
* go1.23-openssl-debuginfo-1.23.12-150600.13.9.1
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* go1.23-openssl-1.23.12-150600.13.9.1
* go1.23-openssl-doc-1.23.12-150600.13.9.1
* go1.23-openssl-race-1.23.12-150600.13.9.1
* go1.23-openssl-debuginfo-1.23.12-150600.13.9.1
* bsc#1229122
* bsc#1236045
* bsc#1236046
* bsc#1236801
* bsc#1238572
* bsc#1240550
* bsc#1244156
* bsc#1244157
* bsc#1246118
* bsc#1247719
* bsc#1247720
* bsc#1247816
* jsc#SLE-18320
## References:
* https://www.suse.com/security/cve/CVE-2024-45336.html
* https://www.suse.com/security/cve/CVE-2024-45341.html
* https://www.suse.com/security/cve/CVE-2025-0913.html
* https://www.suse.com/security/cve/CVE-2025-22866.html
* https://www.suse.com/security/cve/CVE-2025-22870.html
* https://www.suse.com/security/cve/CVE-2025-22871.html
* https://www.suse.com/security/cve/CVE-2025-4673.html
* https://www.suse.com/security/cve/CVE-2025-4674.html
* https://www.suse.com/security/cve/CVE-2025-47906.html
* https://www.suse.com/security/cve/CVE-2025-47907.html
* https://bugzilla.suse.com/show_bug.cgi?id=1229122
* https://bugzilla.suse.com/show_bug.cgi?id=1236045
* https://bugzilla.suse.com/show_bug.cgi?id=1236046
* https://bugzilla.suse.com/show_bug.cgi?id=1236801
* https://bugzilla.suse.com/show_bug.cgi?id=1238572
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.