Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-23102 http://linux.oracle.com/errata/ELSA-2026-23102.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: delve-1.26.1-2.0.1.el10_2.x86_64.rpm aarch64: delve-1.26.1-2.0.1.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/delve-1.26.1-2.0.1.el10_2.src.rpm Related CVEs: CVE-2026-32280 CVE-2026-32281 CVE-2026-32283 Description of changes: [1.26.1-2.0.1] - Disable DWARF compression which has issues (Alex Burmashev) [1.26.1-2] - Bump _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-8842 http://linux.oracle.com/errata/ELSA-2026-8842.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: delve-1.25.2-3.0.1.el10_1.x86_64.rpm aarch64: delve-1.25.2-3.0.1.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/delve-1.25.2-3.0.1.el10_1.src.rpm Related CVEs: CVE-2026-25679 CVE-2026-27137 Description of changes: [1.25.2-3.0.1] - Disable DWARF compression which has issues (Alex Burmashev) [1.25.2-3] - Rebuild with latest Go _______________________________________________ El-errata mailing list
Important: delve security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8842", "synopsis": "Important: delve security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for delve.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible.\n\nSecurity Fix(es):\n\n* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}, {"ticket": "2445345", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445345", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}, {"name": "CVE-2026-27137", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27137", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-295"}], "references": [], "publishedAt":"2026-04-21T12:07:14.176910Z", "rpms": {"Rocky Linux 10": {"nvras": ["delve-debuginfo-0:1.25.2-3.el10_1.x86_64.rpm", "delve-debugsource-0:1.25.2-3.el10_1.aarch64.rpm", "delve-debuginfo-0:1.25.2-3.el10_1.aarch64.rpm", "delve-0:1.25.2-3.el10_1.ppc64le.rpm", "delve-0:1.25.2-3.el10_1.aarch64.rpm", "delve-0:1.25.2-3.el10_1.src.rpm", "delve-debugsource-0:1.25.2-3.el10_1.x86_64.rpm", "delve-debuginfo-0:1.25.2-3.el10_1.ppc64le.rpm", "delve-0:1.25.2-3.el10_1.x86_64.rpm", "delve-debugsource-0:1.25.2-3.el10_1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Delve security update addresses critical issues affecting Rocky Linux 10 with vital fixes for strong protection and functionality.. Delve Security Update, Rocky Linux 10, Important Security Fixes, Application Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-3864 http://linux.oracle.com/errata/ELSA-2026-3864.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: delve-1.25.2-2.0.1.el10_1.x86_64.rpm aarch64: delve-1.25.2-2.0.1.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/delve-1.25.2-2.0.1.el10_1.src.rpm Related CVEs: CVE-2025-61726 CVE-2025-61729 CVE-2025-68121 Description of changes: [1.25.2-2.0.1] - Disable DWARF compression which has issues (Alex Burmashev) [1.25.2-2] - Rebuild with latest Go _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-3842 http://linux.oracle.com/errata/ELSA-2026-3842.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: delve-1.25.2-2.0.1.el9_7.x86_64.rpm aarch64: delve-1.25.2-2.0.1.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/delve-1.25.2-2.0.1.el9_7.src.rpm Related CVEs: CVE-2025-68121 Description of changes: [1.25.2-2.0.1] - Disable DWARF compression which has issues (Alex Burmashev) [1.25.2-2] - Rebuild without changes. - Resolves: RHEL-153104 _______________________________________________ El-errata mailing list
Important: delve security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3864", "synopsis": "Important: delve security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for delve.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible.\n\nSecurity Fix(es):\n\n* crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)\n\n* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2434432", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "description": ""}, {"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}, {"ticket": "2418462", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", "description": ""}], "cves": [{"name": "CVE-2025-61726", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61726", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2025-61729", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2025-61729", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1050"}, {"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-07T12:07:41.291046Z", "rpms": {"Rocky Linux 10": {"nvras": ["delve-0:1.25.2-2.el10_1.src.rpm", "delve-0:1.25.2-2.el10_1.x86_64.rpm", "delve-debugsource-0:1.25.2-2.el10_1.aarch64.rpm", "delve-0:1.25.2-2.el10_1.ppc64le.rpm", "delve-debuginfo-0:1.25.2-2.el10_1.aarch64.rpm", "delve-0:1.25.2-2.el10_1.aarch64.rpm", "delve-debuginfo-0:1.25.2-2.el10_1.ppc64le.rpm", "delve-debugsource-0:1.25.2-2.el10_1.x86_64.rpm", "delve-debugsource-0:1.25.2-2.el10_1.ppc64le.rpm", "delve-debuginfo-0:1.25.2-2.el10_1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important delve security fix in Rocky Linux 10 addresses Denial of Service and memory exhaustion issues. Update recommended.. Delve Debugger, Rocky Linux Security, Software Update, Memory Exhaustion, Denial of Service. . Severity: Important. LinuxSecurity.com Team
Moderate: delve security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3842", "synopsis": "Moderate: delve security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for delve.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible.\n\nSecurity Fix(es):\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}], "cves": [{"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-06T12:03:43.669647Z", "rpms": {"Rocky Linux 9": {"nvras": ["delve-0:1.25.2-2.el9_7.aarch64.rpm", "delve-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-0:1.25.2-2.el9_7.src.rpm", "delve-0:1.25.2-2.el9_7.x86_64.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.aarch64.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.x86_64.rpm", "delve-debugsource-0:1.25.2-2.el9_7.aarch64.rpm", "delve-debugsource-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-debugsource-0:1.25.2-2.el9_7.x86_64.rpm"]}},"rebootSuggested": false, "buildReferences": []}. Delve security update available for Rocky Linux 9 addresses moderate risks. Enhance your system's defenses with this patch.. Delve security, Rocky Linux updates, security patches, moderate vulnerabilities, blockchain security. . LinuxSecurity.com Team
Support for Go 1.26 and security fixes. Upstream release notes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6d4139dafe 2026-01-01 01:07:37.402497+00:00 -------------------------------------------------------------------------------- Name : delve Product : Fedora 42 Version : 1.26.0 Release : 1.fc42 URL : https://github.com/go-delve/delve Summary : A debugger for the Go programming language Description : Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible. -------------------------------------------------------------------------------- Update Information: Support for Go 1.26 and security fixes. Upstream release notes. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 19 2025 Packit - 1.26.0-1 - Update to 1.26.0 upstream release * Fri Oct 10 2025 Alejandro Sez - 1.25.2-2 - rebuild * Wed Aug 27 2025 Packit - 1.25.2-1 - Update to 1.25.2 upstream release - Resolves: rhbz#2391351 * Fri Aug 15 2025 Maxwell G - 1.25.1-5 - Rebuild for golang-1.25.0 * Fri Aug 15 2025 Maxwell G - 1.25.1-4 - Revert "Rebuild for golang-1.25.0" * Fri Aug 15 2025 Maxwell G - 1.25.1-3 - Rebuild for golang-1.25.0 * Wed Jul 23 2025 Fedora Release Engineering - 1.25.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2399350 - CVE-2025-47906 delve: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399350 [ 2 ] Bug #2407876 - CVE-2025-58189 delve: go crypto/tls ALPN negotiation error contains attackercontrolled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2407876 [ 3 ] Bug #2408153 - CVE-2025-58189 delve: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408153 [ 4 ] Bug #2409344 - CVE-2025-61723 delve: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409344 [ 5 ] Bug #2409623 - CVE-2025-61723 delve: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409623 [ 6 ] Bug #2410295 - CVE-2025-58185 delve: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410295 [ 7 ] Bug #2410574 - CVE-2025-58185 delve: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410574 [ 8 ] Bug #2411208 - CVE-2025-58188 delve: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411208 [ 9 ] Bug #2411472 - CVE-2025-58188 delve: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411472 [ 10 ] Bug #2423981 - delve-1.26.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2423981 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6d4139dafe' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Delve 1.26.0 on Fedora 42 brings critical security fixes and supports Go 1.26, ensuring a safer programming environment.. delve debugger, Go programming, Fedora security, security patches. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.