Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE go1.24 Important Patch for Denial of Service CVE-2025-61726

suse
Calendar Grey January 22, 2026
Dist Suse Esm H88
Install SUSE security update for go1.24 to fix six issues and enhance system safety now.
An update that solves six vulnerabilities and has one security fix can now be installed.

Summary

## This update for go1.24 fixes the following issues: Update to go1.24.12 (released 2026-01-15) (bsc#1236217) Security fixes: * CVE-2025-61730: crypto/tls: handshake messages may be processed at the incorrect encryption level (bsc#1256821). * CVE-2025-68119: cmd/go: unexpected code execution when invoking toolchain (bsc#1256820). * CVE-2025-61731: cmd/go: bypass of flag sanitization can lead to arbitrary code execution (bsc#1256819). * CVE-2025-61726: net/http: memory exhaustion in Request.ParseForm (bsc#1256817). * CVE-2025-61728: archive/zip: denial of service when parsing arbitrary ZIP archives (bsc#1256816). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration

References

* bsc#1236217

* bsc#1256816

* bsc#1256817

* bsc#1256818

* bsc#1256819

* bsc#1256820

* bsc#1256821

Cross-

* CVE-2025-61726

* CVE-2025-61728

* CVE-2025-61730

* CVE-2025-61731

* CVE-2025-68119

* CVE-2025-68121

CVSS scores:

* CVE-2025-61726 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-61726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-61728 ( SUSE ): 6.7

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-61728 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-61730 ( SUSE ): 2.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2025-61730 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

* CVE-2025-61731 ( SUSE ): 7.1

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0219-1
Release Date: 2026-01-22T12:14:15Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here