SUSE SLED15 / SLES15 Security Update : go1.25 (SUSE-SU-2026:3640-1)

high Nessus Plugin ID 337975

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3640-1 advisory.

Security issues fixed:

- CVE-2026-33818: encoding/asn1: enforce maximum recursion depth (bsc#1275034).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609).
- CVE-2026-56853: net/http: apply ReadHeaderTimeout when doing unencrypted HTTP/2 check (bsc#1275028).
- CVE-2026-56858: html/template: fix Javascript regexp context tracking (bsc#1275033).
- CVE-2026-56859: encoding/xml: add recursion depth guard during decode (bsc#1275026).
- CVE-2026-56860: net/url: avoid quadratic complexity in resolvePath (bsc#1275029).
- CVE-2026-56862: crypto/tls: limit handshake messages we are willing to accept post-handshake (bsc#1275032).
- CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).
- CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification bypass (bsc#1275024).

Non security issue fixed:

- go1.25 release tracking (bsc#1244485).

Changes for go1.25:

- update to go1.25.13
* go#79875 cmd/compile: prove misscompilation in slicemask folding leaves garbage in upper bits
* go#80098 cmd/compile: internal compiler error invalid heap allocated var without Heapaddr
* go#80364 os: Root's MkdirAll can't create paths ending in forward slashes
* go#80366 os: TestRootMultiReadFile fails on netbsd/arm64 after CL 797880
* go#80368 os: TestRootConsistencyRemoveAll fails on Plan 9 after CL 797880
* go#80393 runtime: arm64 found pointer to free object with safe code
* go#80440 runtime: uninitialized register due to wrong ABI in mach_vm_region_trampoline leads to libc following garbage stack data as a pointer
* go#80477 cmd/compile: riscv64 miscompiles struct copy, corrupting a []byte slice field
* go#80500 runtime: js/wasm: 'found bad pointer in Go heap' -- link-layout-constant value recorded as a pointer in the write-barrier buffer
* go#80578 cmd/compile: regalloc uses unreliable type data (like v.Type.IsSigned()) to choose the restore of spills
* go#80605 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement
* go#80614 cmd/compile: mips64le misscompile OffPtr by a const which doesn't fit 32bits resulting in panic
* go#80616 cmd/compile: mips/mips64, multiply/divide results spilled from HI/LO corrupted w/ big stack frames
* go#80618 cmd/compile: prove bug causes invalid indirect call
* go#80737 runtime: fpTracebackPartialExpand SIGSEGV under high panic load

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected go1.25, go1.25-doc and / or go1.25-race packages.

See Also

https://bugzilla.suse.com/1244485

https://bugzilla.suse.com/1266609

https://bugzilla.suse.com/1275024

https://bugzilla.suse.com/1275025

https://bugzilla.suse.com/1275026

https://bugzilla.suse.com/1275028

https://bugzilla.suse.com/1275029

https://bugzilla.suse.com/1275032

https://bugzilla.suse.com/1275033

https://bugzilla.suse.com/1275034

https://lists.suse.com/pipermail/sle-updates/2026-August/049370.html

https://www.suse.com/security/cve/CVE-2026-33818

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-56853

https://www.suse.com/security/cve/CVE-2026-56858

https://www.suse.com/security/cve/CVE-2026-56859

https://www.suse.com/security/cve/CVE-2026-56860

https://www.suse.com/security/cve/CVE-2026-56862

https://www.suse.com/security/cve/CVE-2026-56864

https://www.suse.com/security/cve/CVE-2026-56865

Plugin Details

Severity: High

ID: 337975

File Name: suse_SU-2026-3640-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/19/2026

Updated: 8/19/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.17

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-39821

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-56865

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:go1.25-doc, p-cpe:/a:novell:suse_linux:go1.25-race, p-cpe:/a:novell:suse_linux:go1.25

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/18/2026

Vulnerability Publication Date: 5/12/2026

Reference Information

CVE: CVE-2026-33818, CVE-2026-39821, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865

SuSE: SUSE-SU-2026:3640-1