Все бюллетени/p11/ALT-PU-2026-10640-2
ALT-PU-2026-10640-2

Обновление пакета golang в ветке p11

Версия1.26.5-alt1
Задание#424600
Опубликовано2026-07-09
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (2)

CVE-2026-39822
HIGH7.8

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Опубликовано: 2026-07-08Изменено: 2026-07-08
CVSS 3.xВЫСОКАЯ 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-42505
MEDIUM5.3

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

Опубликовано: 2026-07-08Изменено: 2026-07-08
CVSS 3.xСРЕДНЯЯ 5.3
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N