Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE go1.25-openssl Important Update Patch 2026-0297-1 Denial of Service

suse
Calendar Grey January 27, 2026
Dist Suse Esm H88
This security advisory details an important update for go1.25-openssl addressing 22 issues and enhancing system security.
An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

Summary

## This update for go1.25-openssl fixes the following issues: Update to version 1.25.6 (released 2026-01-15) (jsc#SLE-18320, bsc#1244485): Security fixes: * CVE-2025-4674 cmd/go: disable support for multiple vcs in one module (bsc#1246118). * CVE-2025-47906 os/exec: LookPath bug: incorrect expansion of "", "." and ".." in some PATH configurations (bsc#1247719). * CVE-2025-47907 database/sql: incorrect results returned from Rows.Scan (bsc#1247720). * CVE-2025-47910 net/http: CrossOriginProtection insecure bypass patterns not limited to exact matches (bsc#1249141). * CVE-2025-47912 net/url: insufficient validation of bracketed IPv6 hostnames (bsc#1251257). * CVE-2025-58183 archive/tar: unbounded allocation when parsing GNU sparse map (bsc#1251261).

References

* bsc#1244485

* bsc#1245878

* bsc#1246118

* bsc#1247719

* bsc#1247720

* bsc#1247816

* bsc#1248082

* bsc#1249141

* bsc#1249985

* bsc#1251253

* bsc#1251254

* bsc#1251255

* bsc#1251256

* bsc#1251257

* bsc#1251258

* bsc#1251259

* bsc#1251260

* bsc#1251261

* bsc#1251262

* bsc#1254227

* bsc#1254430

* bsc#1254431

* bsc#1256816

* bsc#1256817

* bsc#1256818

* bsc#1256819

* bsc#1256820

* bsc#1256821

* jsc#SLE-18320

Cross-

* CVE-2025-4674

* CVE-2025-47906

* CVE-2025-47907

* CVE-2025-47910

* CVE-2025-47912

* CVE-2025-58183

* CVE-2025-58185

* CVE-2025-58186

* CVE-2025-58187

* CVE-2025-58188

* CVE-2025-58189

* CVE-2025-61723

* CVE-2025-61724

* CVE-2025-61725

* CVE-2025-61726

* CVE-2025-61727

* CVE-2025-61728

* CVE-2025-61729

* CVE-2025-61730

* CVE-2025-61731

* CVE-2025-68119

* CVE-2025-68121

CVSS scores:

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0297-1
Release Date: 2026-01-26T16:10:55Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here