Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE Linux Enterprise Server 15 SP4 Important Security Update 2026-0218-1

suse
Calendar Grey January 22, 2026
Dist Suse Esm H88
This advisory covers important security updates for go1.25 addressing critical vulnerabilities to enhance system security.
An update that solves six vulnerabilities and has one security fix can now be installed.

Summary

## This update for go1.25 fixes the following issues: Update to go1.25.6 (released 2026-01-15) (bsc#1244485) Security fixes: * CVE-2025-61730: crypto/tls: handshake messages may be processed at the incorrect encryption level (bsc#1256821). * CVE-2025-68119: cmd/go: unexpected code execution when invoking toolchain (bsc#1256820). * CVE-2025-61731: cmd/go: bypass of flag sanitization can lead to arbitrary code execution (bsc#1256819). * CVE-2025-61726: net/http: memory exhaustion in Request.ParseForm (bsc#1256817). * CVE-2025-61728: archive/zip: denial of service when parsing arbitrary ZIP archives (bsc#1256816). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration

References

* bsc#1244485

* bsc#1256816

* bsc#1256817

* bsc#1256818

* bsc#1256819

* bsc#1256820

* bsc#1256821

Cross-

* CVE-2025-61726

* CVE-2025-61728

* CVE-2025-61730

* CVE-2025-61731

* CVE-2025-68119

* CVE-2025-68121

CVSS scores:

* CVE-2025-61726 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-61726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-61728 ( SUSE ): 6.7

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-61728 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-61730 ( SUSE ): 2.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2025-61730 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

* CVE-2025-61731 ( SUSE ): 7.1

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0218-1
Release Date: 2026-01-22T12:13:12Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here