Alerts This Week
Warning Icon 1 1,154
Alerts This Week
Warning Icon 1 1,154

SUSE Linux Enterprise 16.0 Security Update Go1.25 Important 2026-20132-1

suse
Calendar Grey January 28, 2026
Dist Suse Esm H88
A significant security update for go1.25 resolves six issues that could lead to denial of service and code execution vulnerabilities.
An update that solves six vulnerabilities and has one fix can now be installed.

Summary

## This update for go1.25 fixes the following issues: Update to go1.25.6 (released 2026-01-15) (bsc#1244485) Security fixes: * CVE-2025-61730: crypto/tls: handshake messages may be processed at the incorrect encryption level (bsc#1256821). * CVE-2025-68119: cmd/go: unexpected code execution when invoking toolchain (bsc#1256820). * CVE-2025-61731: cmd/go: bypass of flag sanitization can lead to arbitrary code execution (bsc#1256819). * CVE-2025-61726: net/http: memory exhaustion in Request.ParseForm (bsc#1256817). * CVE-2025-61728: archive/zip: denial of service when parsing arbitrary ZIP archives (bsc#1256816). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration

References

* bsc#1244485

* bsc#1256816

* bsc#1256817

* bsc#1256818

* bsc#1256819

* bsc#1256820

* bsc#1256821

Cross-

* CVE-2025-61726

* CVE-2025-61728

* CVE-2025-61730

* CVE-2025-61731

* CVE-2025-68119

* CVE-2025-68121

CVSS scores:

* CVE-2025-61726 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-61726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-61728 ( SUSE ): 6.7

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-61728 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-61730 ( SUSE ): 2.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2025-61730 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

* CVE-2025-61731 ( SUSE ): 7.1

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:20132-1
Release Date: 2026-01-22T15:49:20Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here