[CLSA-2026:1785498146] golang: Fix of CVE-2026-32288
Type:
security
Severity:
Moderate
Release date:
2026-07-31 11:42:35 UTC
Description:
- CVE-2026-32288: fix unbounded memory allocation in archive/tar when reading old GNU sparse maps by bounding the cumulative size of the sparse extension blocks and capping the total number of sparse entries in all sparse formats
CVEs fixed:
Updated packages:
  • go-toolset-1.25.7-1.el9_6.tuxcare.els15.x86_64.rpm
    sha:a96c5be597b9a441ae2ae9ebf2f850dae17655bbba545350f88ce18e93c0ad8c
  • golang-1.25.7-1.el9_6.tuxcare.els15.x86_64.rpm
    sha:1da39c1c2bf537203c7f56aa43ae90f3e9743dbc21194475bb1359f3dca8c353
  • golang-bin-1.25.7-1.el9_6.tuxcare.els15.x86_64.rpm
    sha:29b2543a886ffc169498b814f677ab5a07d4b2eaef773e9befcc25972b1dff4d
  • golang-docs-1.25.7-1.el9_6.tuxcare.els15.noarch.rpm
    sha:64fa0a8c0d472afcf746bfa13cf2ed7085ed6dbb8cdd103bd75d0e40190a7537
  • golang-misc-1.25.7-1.el9_6.tuxcare.els15.noarch.rpm
    sha:67d4fa701333e31ff90d949186882ae7aa0a5de804ef79c5ffab8c72d942cc0a
  • golang-race-1.25.7-1.el9_6.tuxcare.els15.x86_64.rpm
    sha:cf4fd1ffff75b9cf8eb5c2440494993ea36103907d5f7aa51f862413cca38a24
  • golang-src-1.25.7-1.el9_6.tuxcare.els15.noarch.rpm
    sha:16a5a8e036f575df36bc6345a6f53ce60fe3f37d6274b7125e850c5ae12a7811
  • golang-tests-1.25.7-1.el9_6.tuxcare.els15.noarch.rpm
    sha:7c7c7e97a2376fa78b1535a50e07b480d285d49fbb4713b20163b2a84e3e916b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.