[CLSA-2026:1784533387] golang: Fix of CVE-2026-39821
Type:
security
Severity:
Important
Release date:
2026-07-20 07:43:30 UTC
Description:
- CVE-2026-39821: reject all-ASCII xn-- labels in the vendored golang.org/x/net/idna to prevent Punycode label spoofing
CVEs fixed:
Updated packages:
  • go-toolset-1.22.9-1.el9_2.tuxcare.els19.x86_64.rpm
    sha:6b444422a25054a088a4befde5a5d26a4897c5a9320c6b01346f4b399239bf7b
  • golang-1.22.9-1.el9_2.tuxcare.els19.x86_64.rpm
    sha:ac5cee2232d9d205b4a9414212bcc520fb19e18cdb99248feae0ca9006fef194
  • golang-bin-1.22.9-1.el9_2.tuxcare.els19.x86_64.rpm
    sha:4caf5421f726cbac31e416f5de180fbd02add576c02a8ce92dc1f47b67e68fd2
  • golang-docs-1.22.9-1.el9_2.tuxcare.els19.noarch.rpm
    sha:1b6a7843d0342c6061805e0ae80e93f2ae82a7cd3793806203e7a83d868f81aa
  • golang-misc-1.22.9-1.el9_2.tuxcare.els19.noarch.rpm
    sha:685992541a97fe9fa6a3e2cfd1eb0fb25c5f2053f90f2c4fb326c3be7bf32a6b
  • golang-src-1.22.9-1.el9_2.tuxcare.els19.noarch.rpm
    sha:5f67bd5cb82ff41a6a796e6f833039f628c8c6cec74985d66b8aa668edc322a2
  • golang-tests-1.22.9-1.el9_2.tuxcare.els19.noarch.rpm
    sha:9016c27994cfbbad4db6c1cf7bb4e8134ee435a8c05e19ea761f3a081eefdfaf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.