Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE Linux 15 SP7 go1.24-openssl Important DoS Issues 2026-0308-1

suse
Calendar Grey January 28, 2026
Dist Suse Esm H88
Install the important security update for go1.24-openssl on SUSE with multiple issue fixes and enhancements.
An update that solves 18 vulnerabilities, contains one feature and has five security fixes can now be installed.

Summary

## This update for go1.24-openssl fixes the following issues: Update to version 1.24.12 (released 2026-01-15) (jsc#SLE-18320, bsc#1236217): Security fixes: * CVE-2025-47912: net/url: insufficient validation of bracketed IPv6 hostnames (bsc#1251257). * CVE-2025-58183: archive/tar: unbounded allocation when parsing GNU sparse map (bsc#1251261). * CVE-2025-58185: encoding/asn1: pre-allocating memory when parsing DER payload can cause memory exhaustion (bsc#1251258). * CVE-2025-58186: net/http: lack of limit when parsing cookies can cause memory exhaustion (bsc#1251259). * CVE-2025-58187: crypto/x509: quadratic complexity when checking name constraints (bsc#1251254). * CVE-2025-58188: crypto/x509: panic when validating certificates with DSA public keys (bsc#1251260).

References

* bsc#1236217

* bsc#1245878

* bsc#1247816

* bsc#1248082

* bsc#1249985

* bsc#1251253

* bsc#1251254

* bsc#1251255

* bsc#1251256

* bsc#1251257

* bsc#1251258

* bsc#1251259

* bsc#1251260

* bsc#1251261

* bsc#1251262

* bsc#1254430

* bsc#1254431

* bsc#1256816

* bsc#1256817

* bsc#1256818

* bsc#1256819

* bsc#1256820

* bsc#1256821

* jsc#SLE-18320

Cross-

* CVE-2025-47912

* CVE-2025-58183

* CVE-2025-58185

* CVE-2025-58186

* CVE-2025-58187

* CVE-2025-58188

* CVE-2025-58189

* CVE-2025-61723

* CVE-2025-61724

* CVE-2025-61725

* CVE-2025-61726

* CVE-2025-61727

* CVE-2025-61728

* CVE-2025-61729

* CVE-2025-61730

* CVE-2025-61731

* CVE-2025-68119

* CVE-2025-68121

CVSS scores:

* CVE-2025-47912 ( SUSE ): 8.8

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0308-1
Release Date: 2026-01-28T08:38:49Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here