AlmaLinux 9.2 [TuxCare] Security Update: go-toolset / golang / golang-bin / golang-docs / golang-misc / etc Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2026:1786527041)

medium Nessus Plugin ID 360010

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2026:1786527041 advisory.

- Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to *.example.com, a request to [::1%25.example.com]:80` will incorrectly match and not be proxied. (CVE-2025-22870)

- The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: http://[::1]/. IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement. (CVE-2025-47912)

- Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion. (CVE-2025-58185)

- When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped. (CVE-2025-58189)

- The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
(CVE-2025-61724)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2026:1786527041.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1786527041

http://www.nessus.org/u?3474b4e4

Plugin Details

Severity: Medium

ID: 360010

File Name: tuxcare_alma_linux_9.2_CLSA-2026-1786527041.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.23

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-32288

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/12/2026

Vulnerability Publication Date: 3/8/2025

Reference Information

CVE: CVE-2025-22870, CVE-2025-47912, CVE-2025-58185, CVE-2025-58189, CVE-2025-61724, CVE-2025-61730, CVE-2026-25679, CVE-2026-32288

CLSA: 2026:1786527041