AlmaLinux 9.2 [TuxCare] Security Update: go-toolset / golang / golang-bin / golang-docs / golang-misc / etc Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2026:1781080840)

medium Nessus Plugin ID 352453

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2026:1781080840 advisory.

- The go tool pack subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the pack subcommand can write files to arbitrary locations on the filesystem. (CVE-2026-39817)

- The go bug command writes to two files with predictable names in the system temporary directory (for example, /tmp). An attacker with access to the temporary directory can create a symlink in one of these names, causing go bug to overwrite the target of the symlink. (CVE-2026-39819)

- ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query a1=x&a2=x&...&a10000=x&hidden=y can forward the parameter hidden=y while hiding it from the proxy's Rewrite function. (CVE-2026-39825)

- If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block. (CVE-2026-39826)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2026:1781080840.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1781080840

http://www.nessus.org/u?fa7daa79

Plugin Details

Severity: Medium

ID: 352453

File Name: tuxcare_alma_linux_9.2_CLSA-2026-1781080840.nasl

Version: 1.1

Type: Local

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.69

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2026-39817

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 6/10/2026

Vulnerability Publication Date: 5/7/2026

Reference Information

CVE: CVE-2026-39817, CVE-2026-39819, CVE-2026-39825, CVE-2026-39826

CLSA: 2026:1781080840