Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE Linux 15 SP7 Go1.26 Important DDoS Issues 2026-1861-1

suse
Calendar Grey May 15, 2026
Dist Suse Esm H88
Critical update for SUSE addressing 11 issues in go1.26 with important ratings and security fixes available.
An update that solves 11 vulnerabilities and has two security fixes can now be installed.

Summary

## This update for go1.26 fixes the following issues Security issues: * CVE-2026-33811: net: crash when handling long CNAME response (bsc#1264508). * CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1264506). * CVE-2026-39817: cmd/go: "go tool pack" does not sanitize output paths (bsc#1264505). * CVE-2026-39819: cmd/go: "go bug" follows symlinks in predictable temporary filenames (bsc#1264504). * CVE-2026-39820: net/mail: quadratic string concatentation in consumeComment (bsc#1264503). * CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509). * CVE-2026-39825: net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters (bsc#1264500).

References

* bsc#1170826

* bsc#1255111

* bsc#1264499

* bsc#1264500

* bsc#1264501

* bsc#1264502

* bsc#1264503

* bsc#1264504

* bsc#1264505

* bsc#1264506

* bsc#1264507

* bsc#1264508

* bsc#1264509

Cross-

* CVE-2026-33811

* CVE-2026-33814

* CVE-2026-39817

* CVE-2026-39819

* CVE-2026-39820

* CVE-2026-39823

* CVE-2026-39825

* CVE-2026-39826

* CVE-2026-39836

* CVE-2026-42499

* CVE-2026-42501

CVSS scores:

* CVE-2026-33811 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1861-1
Release Date: 2026-05-14T22:33:22Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here