Rocky Linux 9.6 [TuxCare] Security Update: go-toolset / golang / golang-bin / golang-docs / golang-misc / etc Multiple Vulnerabilities (ALMALINUX9.6:CLSA-2026:1781256571)

medium Nessus Plugin ID 362041

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 9.6 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.6:CLSA-2026:1781256571 advisory.

- Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value refresh. A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow url= by setting htmlmetacontenturlescape=0. (CVE-2026-27142)

- The go tool pack subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the pack subcommand can write files to arbitrary locations on the filesystem. (CVE-2026-39817)

- The go bug command writes to two files with predictable names in the system temporary directory (for example, /tmp). An attacker with access to the temporary directory can create a symlink in one of these names, causing go bug to overwrite the target of the symlink. (CVE-2026-39819)

- CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS. (CVE-2026-39823)

- ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query a1=x&a2=x&...&a10000=x&hidden=y can forward the parameter hidden=y while hiding it from the proxy's Rewrite function. (CVE-2026-39825)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.6:CLSA-2026:1781256571.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1781256571

http://www.nessus.org/u?c3ce767d

Plugin Details

Severity: Medium

ID: 362041

File Name: tuxcare_rocky_linux_9.6_CLSA-2026-1781256571.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.94

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2026-39817

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Ease: No known exploits are available

Patch Publication Date: 6/12/2026

Vulnerability Publication Date: 3/5/2026

Reference Information

CVE: CVE-2026-27142, CVE-2026-39817, CVE-2026-39819, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826

CLSA: 2026:1781256571