[CLSA-2026:1772039226] golang: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-02-25 17:07:12 UTC
Description:
- CVE-2025-61726: limit parsed URL query parameters to mitigate excessive memory consumption during form parsing - CVE-2025-61732: prevent cgo code smuggling by removing user-controlled content from documentation strings in generated ASTs
Updated packages:
  • go-toolset-1.22.9-1.el9_2.tuxcare.els5.x86_64.rpm
    sha:2a83bce81daa8dd4ac283816ef238d297b05f1bb36d7254d48716356a9b0ff97
  • golang-1.22.9-1.el9_2.tuxcare.els5.x86_64.rpm
    sha:1a522ceecd2b4af1c75114d1ea596b6461b133aa16c12af1a7b146026228ce33
  • golang-bin-1.22.9-1.el9_2.tuxcare.els5.x86_64.rpm
    sha:f58738b623d66e2cfef11f9f94d6ad6d2d3b4bb4a3fb88fde570d34870d10a1c
  • golang-docs-1.22.9-1.el9_2.tuxcare.els5.noarch.rpm
    sha:11c3a6e947c7a61c8c03636d2a15244cd82f0145a4ebf6c94841c45db4a1f93f
  • golang-misc-1.22.9-1.el9_2.tuxcare.els5.noarch.rpm
    sha:88a3b7cc473f563d2f296a51c1da91ee86406ccb9c0536bd1661f42f6d1fcf82
  • golang-src-1.22.9-1.el9_2.tuxcare.els5.noarch.rpm
    sha:3ce54b96a76c9b958e65dbf39ced7da4b8d9992641d1f6f7c22b75326ff7d147
  • golang-tests-1.22.9-1.el9_2.tuxcare.els5.noarch.rpm
    sha:7c39fddd50a3c67fe7e7e1acf4307d2b3d5e6587a4bb38bc04c2946483ed4565
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.