Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:16694: Important: go-toolset:rhel8 security update

A vulnerability (CVE-2026-27140, CVSS 8.8 HIGH) in the Go toolset's `cmd/go` component allows arbitrary code execution via malicious SWIG file names. The affected version ranges are Go (golang) versions prior to 1.25.9, and versions 1.26.0 through 1.26.1. The flaw is remediated by upgrading to Go version 1.25.9 or 1.26.2.
Read Full Article →

Red Hat Product Errata RHSA-2026:16694 - Security Advisory Issued: 2026-05-13 Updated: 2026-05-13 RHSA-2026:16694 - Security Advisory Overview Updated Packages Synopsis Important: go-toolset:rhel8 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names (CVE-2026-27140) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2456341 - CVE-2026-27140 cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names CVEs CVE-2026-27140 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM delve-1.9.1-1.module+el8.8.0+16778+5fbb74f5.src.rpm SHA-256: 1b037c6c0f16e789c9cf361b6cf87e5e06661e7f29deae013bb1ede7f3c1ff93 go-toolset-1.19.13-4.module+el8.8.0+23976+18ba1869.src.rpm SHA-256: dac75b6eb9a22737b168e1a5ef00d4d726b92508ee24ec704e402ba5e9aa7180 golang-1.19.13-24.module+el8.8.0+24268+9f9e0e19.src.rpm SHA-256: 41b6983c2696f12691b976afcbb85291ce09561a99aad4e6264f36a0879ee37b x86_64 golang-docs-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: b0245ad6a276627c5c369279ed8b12552a61238a74a640879ce5251c13d5f1bc golang-misc-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: cd3e74b4be518e74c70cc972aeb69b99e854542d946957bc64fa8e1b606dd186 golang-src-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: a10060177a9b46ad2b003bbc845bd00dc1c0357ebabe77dc4ec3ef831f84ba34 golang-tests-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: 30160cc3b0df82cfba16d4ecd54639ea3bea7a7f8e21d737418a6de77ecdc772 delve-1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64.rpm SHA-256: e63fbb1595650d32386fe757c131a9475710f50f3df6c673b9ee3d7da17fb40b delve-debuginfo-1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64.rpm SHA-256: 10cbdf420e26f44c6a556c9bac32f8d4d9f55f2c1294009710248550c0ed1528 delve-debugsource-1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64.rpm SHA-256: b9ec866e5579c7683dfc4a6efd2fb41b21e3635de5fac94c4f9870f647f9c869 go-toolset-1.19.13-4.module+el8.8.0+23976+18ba1869.x86_64.rpm SHA-256: 613e7de04d8799b3e33ab7d5617ce889ed5bcf06d2e2af79db65414dd233a9db golang-1.19.13-24.module+el8.8.0+24268+9f9e0e19.x86_64.rpm SHA-256: 2dbbc26713ca8cc32e9540c6728ba26d71d85fdef4fe25b4a73d1bc6f9e25e6b golang-bin-1.19.13-24.module+el8.8.0+24268+9f9e0e19.x86_64.rpm SHA-256: 957288809db5bf3bf7089fc9c235bdd61d99c5fbe583f203f5a38e8a55dc1257 golang-docs-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: b0245ad6a276627c5c369279ed8b12552a61238a74a640879ce5251c13d5f1bc golang-misc-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: cd3e74b4be518e74c70cc972aeb69b99e854542d946957bc64fa8e1b606dd186 golang-race-1.19.13-24.module+el8.8.0+24268+9f9e0e19.x86_64.rpm SHA-256: 1d46984f6ec150332e5fe872041b46fa912e36a94b9e61f9338949825d1ff668 golang-src-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: a10060177a9b46ad2b003bbc845bd00dc1c0357ebabe77dc4ec3ef831f84ba34 golang-tests-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: 30160cc3b0df82cfba16d4ecd54639ea3bea7a7f8e21d737418a6de77ecdc772 Red Hat Enterprise Linux Server - TUS 8.8 SRPM delve-1.9.1-1.module+el8.8.0+16778+5fbb74f5.src.rpm SHA-256: 1b037c6c0f16e789c9cf361b6cf87e5e06661e7f29deae013bb1ede7f3c1ff93 go-toolset-1.19.13-4.module+el8.8.0+23976+18ba1869.src.rpm SHA-256: dac75b6eb9a22737b168e1a5ef00d4d726b92508ee24ec704e402ba5e9aa7180 golang-1.19.13-24.module+el8.8.0+24268+9f9e0e19.src.rpm SHA-256: 41b6983c2696f12691b976afcbb85291ce09561a99aad4e6264f36a0879ee37b x86_64 golang-docs-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: b0245ad6a276627c5c369279ed8b12552a61238a74a640879ce5251c13d5f1bc golang-misc-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: cd3e74b4be518e74c70cc972aeb69b99e854542d946957bc64fa8e1b606dd186 golang-src-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: a10060177a9b46ad2b003bbc845bd00dc1c0357ebabe77dc4ec3ef831f84ba34 golang-tests-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: 30160cc3b0df82cfba16d4ecd54639ea3bea7a7f8e21d737418a6de77ecdc772 delve-1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64.rpm SHA-256: e63fbb1595650d32386fe757c131a9475710f50f3df6c673b9ee3d7da17fb40b delve-debuginfo-1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64.rpm SHA-256: 10cbdf420e26f44c6a556c9bac32f8d4d9f55f2c1294009710248550c0ed1528 delve-debugsource-1.9.1-1.module+el8.8.0+16778+5fbb74f5.x86_64.rpm SHA-256: b9ec866e5579c7683dfc4a6efd2fb41b21e3635de5fac94c4f9870f647f9c869 go-toolset-1.19.13-4.module+el8.8.0+23976+18ba1869.x86_64.rpm SHA-256: 613e7de04d8799b3e33ab7d5617ce889ed5bcf06d2e2af79db65414dd233a9db golang-1.19.13-24.module+el8.8.0+24268+9f9e0e19.x86_64.rpm SHA-256: 2dbbc26713ca8cc32e9540c6728ba26d71d85fdef4fe25b4a73d1bc6f9e25e6b golang-bin-1.19.13-24.module+el8.8.0+24268+9f9e0e19.x86_64.rpm SHA-256: 957288809db5bf3bf7089fc9c235bdd61d99c5fbe583f203f5a38e8a55dc1257 golang-docs-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: b0245ad6a276627c5c369279ed8b12552a61238a74a640879ce5251c13d5f1bc golang-misc-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: cd3e74b4be518e74c70cc972aeb69b99e854542d946957bc64fa8e1b606dd186 golang-race-1.19.13-24.module+el8.8.0+24268+9f9e0e19.x86_64.rpm SHA-256: 1d46984f6ec150332e5fe872041b46fa912e36a94b9e61f9338949825d1ff668 golang-src-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: a10060177a9b46ad2b003bbc845bd00dc1c0357ebabe77dc4ec3ef831f84ba34 golang-tests-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: 30160cc3b0df82cfba16d4ecd54639ea3bea7a7f8e21d737418a6de77ecdc772 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM go-toolset-1.19.13-4.module+el8.8.0+23976+18ba1869.src.rpm SHA-256: dac75b6eb9a22737b168e1a5ef00d4d726b92508ee24ec704e402ba5e9aa7180 golang-1.19.13-24.module+el8.8.0+24268+9f9e0e19.src.rpm SHA-256: 41b6983c2696f12691b976afcbb85291ce09561a99aad4e6264f36a0879ee37b ppc64le go-toolset-1.19.13-4.module+el8.8.0+23976+18ba1869.ppc64le.rpm SHA-256: 16cb3cb5856aafc9815eec32037b5752a33098a8fc4e1f158672a07bf43bb92a golang-1.19.13-24.module+el8.8.0+24268+9f9e0e19.ppc64le.rpm SHA-256: db8adb85aa47d0347cc87161fa7a9d96bec374044b462f43a9870a384d12daf5 golang-bin-1.19.13-24.module+el8.8.0+24268+9f9e0e19.ppc64le.rpm SHA-256: c8408e2b98b8887ca13b4cbcc548518c9c28974c4512999c84bc531a5707690b golang-docs-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: b0245ad6a276627c5c369279ed8b12552a61238a74a640879ce5251c13d5f1bc golang-misc-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: cd3e74b4be518e74c70cc972aeb69b99e854542d946957bc64fa8e1b606dd186 golang-src-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: a10060177a9b46ad2b003bbc845bd00dc1c0357ebabe77dc4ec3ef831f84ba34 golang-tests-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: 30160cc3b0df82cfba16d4ecd54639ea3bea7a7f8e21d737418a6de77ecdc772 golang-docs-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: b0245ad6a276627c5c369279ed8b12552a61238a74a640879ce5251c13d5f1bc golang-misc-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: cd3e74b4be518e74c70cc972aeb69b99e854542d946957bc64fa8e1b606dd186 golang-src-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: a10060177a9b46ad2b003bbc845bd00dc1c0357ebabe77dc4ec3ef831f84ba34 golang-tests-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: 30160cc3b0df82cfba16d4ecd54639ea3bea7a7f8e21d737418a6de77ecdc772 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM delve-1.9.1-1.module+el8.8.0+16778+5fbb74f5.src.rpm SHA-256: 1b037c6c0f16e789c9cf361b6cf87e5e06661e7f29deae013bb1ede7f3c1ff93 go-toolset-1.19.13-4.module+el8.8.0+23976+18ba1869.src.rpm SHA-256: dac75b6eb9a22737b168e1a5ef00d4d726b92508ee24ec704e402ba5e9aa7180 golang-1.19.13-24.module+el8.8.0+24268+9f9e0e19.src.rpm SHA-256: 41b6983c2696f12691b976afcbb85291ce09561a99aad4e6264f36a0879ee37b x86_64 golang-docs-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: b0245ad6a276627c5c369279ed8b12552a61238a74a640879ce5251c13d5f1bc golang-misc-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: cd3e74b4be518e74c70cc972aeb69b99e854542d946957bc64fa8e1b606dd186 golang-src-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: a10060177a9b46ad2b003bbc845bd00dc1c0357ebabe77dc4ec3ef831f84ba34 golang-tests-1.19.13-24.module+el8.8.0+24268+9f9e0e19.noarch.rpm SHA-256: 30160cc3b0df82cfba16d4ecd54639ea3bea

Share this article