Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

SUSE go1.25-openssl Critical Update for 30 Issues 2026-22638-1

suse
Calendar Grey July 16, 2026
Scroller Suse
A critical security advisory for SUSE details an update for go1.25-openssl addressing 30 vulnerabilities and key enhancements.
A security update for go1.25-openssl addresses 30 vulnerabilities, enhances functionality, and requires installation for affected SUSE Linux Enterprise Server versions.

Summary

## This update for go1.25-openssl fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2025-61732: cmd/cgo: discrepancy between Go and C/C++ comment parsing allows for C code smuggling (bsc#1257692). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain (bsc#1256818). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265).

References

* bsc#1170826

* bsc#1244485

* bsc#1245878

* bsc#1256818

* bsc#1257692

* bsc#1259264

* bsc#1259265

* bsc#1259268

* bsc#1261653

* bsc#1261654

* bsc#1261655

* bsc#1261656

* bsc#1261657

* bsc#1261658

* bsc#1261659

* bsc#1261660

* bsc#1261661

* bsc#1264394

* bsc#1264499

* bsc#1264500

* bsc#1264501

* bsc#1264502

* bsc#1264503

* bsc#1264504

* bsc#1264505

* bsc#1264506

* bsc#1264507

* bsc#1264508

* bsc#1264509

* bsc#1267442

* bsc#1267444

* bsc#1267450

* bsc#1271014

* bsc#1271015

* jsc#PED-1962

* jsc#SLE-18320

Cross-

* CVE-2025-61732

* CVE-2025-68121

* CVE-2026-25679

* CVE-2026-27139

* CVE-2026-27140

* CVE-2026-27142

* CVE-2026-27143

* CVE-2026-27144

* CVE-2026-27145

* CVE-2026-32280

* CVE-2026-32281

* CVE-2026-32282

* CVE-2026-32283

* CVE-2026-32288

* CVE-2026-32289

* CVE-2026-33811

* CVE-2026-33814

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22638-1
Release Date: 2026-07-13T12:52:40Z
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.