RHSA-2026:5944: Important: golang security update
Important: golang security update
Other sources
The golang packages provide the Go programming language compiler.Security Fix(es): cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive (CVE-2025-61731) net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:5944?
The severity of RHSA-2026:5944 is classified as Important due to its potential impact on security.
How do I fix RHSA-2026:5944?
To fix RHSA-2026:5944, update to the package version 1.25.8-1.el9_6 for golang and related packages.
What vulnerabilities are addressed in RHSA-2026:5944?
RHSA-2026:5944 addresses an arbitrary file write vulnerability via malicious pkg-config directive and an incorrect parsing of IPv6 host literals.
Which systems are affected by RHSA-2026:5944?
RHSA-2026:5944 affects various versions of Red Hat Enterprise Linux, including those for x86_64, ARM, and IBM z Systems.
What components are included in the RHSA-2026:5944 update?
The RHSA-2026:5944 update includes key components like golang, go-toolset, golang-bin, and other related packages.