RHSA-2026:29980: Moderate: golang security, bug fix, and enhancement update
Moderate: golang security, bug fix, and enhancement update
Other sources
The golang packages provide the Go programming language compiler.Security Fix(es): net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507) Bug Fix(es) and Enhancement(s): Update Go to version 1.26.4+1 [rhel-10.2.z] (JIRA:RHEL-183347) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2 - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2 - Upgrade
Upgrade
redhat/golang-docsto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2 - Upgrade
Upgrade
redhat/golang-miscto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2 - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2 - Upgrade
Upgrade
redhat/golang-srcto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2 - Upgrade
Upgrade
redhat/golang-teststo a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2.aa - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2.aa - Upgrade
Upgrade
redhat/golang-binto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2.aa - Upgrade
Upgrade
redhat/golang-raceto a version that resolves this vulnerability.Fixed in 1.26.4-1.el10_2.aa - Upgrade
Upgrade
Go (golang)to a version that resolves this vulnerability.Fixed in 1.26.4+1Patch rhel-10.2.z - Compensating control
If Go is used in a context where net/textproto parses untrusted input, treat input as untrusted and validate/sanitize it to reduce the risk of misleading error messages via input injection (CVE-2026-42507) until the Go update is applied.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:29980?
The severity of RHSA-2026:29980 is classified as medium with a score of 4.
What security fix is addressed in RHSA-2026:29980?
RHSA-2026:29980 addresses a misleading error message vulnerability in golang net/textproto identified by CVE-2026-42507.
How do I fix RHSA-2026:29980?
To fix RHSA-2026:29980, update the golang packages to the latest version provided by Red Hat.
What are the affected software packages in RHSA-2026:29980?
Affected software packages include redhat/golang, redhat/go-toolset, redhat/golang-bin, and redhat/golang-race.
What enhancements are included in RHSA-2026:29980?
RHSA-2026:29980 includes bug fixes and enhancements in addition to the security updates for golang.