Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:28038: Important: gvisor-tap-vsock security update

This security update for the gvisor-tap-vsock package addresses multiple vulnerabilities in its underlying Go components, including a high-severity denial-of-service flaw in TLS 1.3 (CVE-2026-32283, CVSS 7.5) and a medium-severity symlink traversal issue (CVE-2026-32282, CVSS 6.4). The affected Go versions are prior to 1.25.9 and from 1.26.0 to before 1.26.2. The fix is included in the updated gvisor-tap-vsock package for Red Hat Enterprise Linux 9.6 Extended Update Support and related variants.
Read Full Article →

Red Hat Product Errata RHSA-2026:28038 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:28038 - Security Advisory Overview Updated Packages Synopsis Important: gvisor-tap-vsock security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gvisor-tap-vsock is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description A replacement for libslirp and VPNKit, written in pure Go. It is based on the network stack of gVisor. Compared to libslirp, gvisor-tap-vsock brings a configurable DNS server and dynamic port forwarding. Security Fix(es): crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2445345 - CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509 BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVEs CVE-2026-27137 CVE-2026-32280 CVE-2026-32282 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM gvisor-tap-vsock-0.8.5-2.el9_6.2.src.rpm SHA-256: cdd00a4410ca5c530371ea57920f6bd0e5d480d26ddb6ae860e48aba1dac03dd x86_64 gvisor-tap-vsock-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: 61de4294460fc6cfc020ecb7bb3436cf26aa104183348cafcb58575cd9e2d85e gvisor-tap-vsock-debuginfo-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: cee38b62f155dcfcbef0090d8b6787fce69bfe3b849a6b4256abf3ee62b786bd gvisor-tap-vsock-debugsource-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: 85de8cdfb52f62683b1258a17d68cc37fe03b6082a994d4386f7fac3108bf2d8 gvisor-tap-vsock-gvforwarder-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: c97adb18dca5bf25440cc3e97351e05939cf801c2d78bd2ffd3f192ee31c90cf gvisor-tap-vsock-gvforwarder-debuginfo-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: d49ea81efce16d8ff0a87c48f2fab996ddac9238c80337f831605f3d5e21f42b Red Hat Enterprise Linux Server - AUS 9.6 SRPM gvisor-tap-vsock-0.8.5-2.el9_6.2.src.rpm SHA-256: cdd00a4410ca5c530371ea57920f6bd0e5d480d26ddb6ae860e48aba1dac03dd x86_64 gvisor-tap-vsock-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: 61de4294460fc6cfc020ecb7bb3436cf26aa104183348cafcb58575cd9e2d85e gvisor-tap-vsock-debuginfo-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: cee38b62f155dcfcbef0090d8b6787fce69bfe3b849a6b4256abf3ee62b786bd gvisor-tap-vsock-debugsource-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: 85de8cdfb52f62683b1258a17d68cc37fe03b6082a994d4386f7fac3108bf2d8 gvisor-tap-vsock-gvforwarder-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: c97adb18dca5bf25440cc3e97351e05939cf801c2d78bd2ffd3f192ee31c90cf gvisor-tap-vsock-gvforwarder-debuginfo-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: d49ea81efce16d8ff0a87c48f2fab996ddac9238c80337f831605f3d5e21f42b Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM gvisor-tap-vsock-0.8.5-2.el9_6.2.src.rpm SHA-256: cdd00a4410ca5c530371ea57920f6bd0e5d480d26ddb6ae860e48aba1dac03dd s390x gvisor-tap-vsock-0.8.5-2.el9_6.2.s390x.rpm SHA-256: e63bc91f5d2bd678bfb110a69adaa5d62d6b1c15cef2827729e3676ee8e3edae gvisor-tap-vsock-debuginfo-0.8.5-2.el9_6.2.s390x.rpm SHA-256: 328ad8ed0ff8001904446dd6976541ae19e0109268bdf72e90b75f0c9ec75a5e gvisor-tap-vsock-debugsource-0.8.5-2.el9_6.2.s390x.rpm SHA-256: 782f9afa4a813f93e8aa6ae51beea7fd8d414d4796e080fdd95747db8b6d257e gvisor-tap-vsock-gvforwarder-0.8.5-2.el9_6.2.s390x.rpm SHA-256: d6bd622a271b4d5875a0ccc748c16c29f250a86f8096b07074ffa1e1886d84c3 gvisor-tap-vsock-gvforwarder-debuginfo-0.8.5-2.el9_6.2.s390x.rpm SHA-256: 685957ab30f4bccb0406e9aa5ce054ab1be11cf671e9ec8c50bd6f128d8bab6f Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM gvisor-tap-vsock-0.8.5-2.el9_6.2.src.rpm SHA-256: cdd00a4410ca5c530371ea57920f6bd0e5d480d26ddb6ae860e48aba1dac03dd ppc64le gvisor-tap-vsock-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: 2d4a2005950035d34708d39b64c57352ade06d6f5cc83fba24d0d0d0e372f85f gvisor-tap-vsock-debuginfo-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: e254c8f0e68d5a671a97242b913af0fa78c476c55e5bd3bc75cb596f7b2648d4 gvisor-tap-vsock-debugsource-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: b59d1d6d1498afbc23ac0c1df97500cca1a65a298234e9ba63155017ed760ff9 gvisor-tap-vsock-gvforwarder-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: 266a5c6f4a9420b8b48caffff7398e4e29facbc59b9d1ce60d7ee7aecc6460b3 gvisor-tap-vsock-gvforwarder-debuginfo-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: 2830f5ce22c208a32fa5e1a0a109d356a1cf00b89a7002b3ba4f75247f1366c1 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 SRPM gvisor-tap-vsock-0.8.5-2.el9_6.2.src.rpm SHA-256: cdd00a4410ca5c530371ea57920f6bd0e5d480d26ddb6ae860e48aba1dac03dd aarch64 gvisor-tap-vsock-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: 2e7c70e010cd4f3b767a8f97d4fb4e4d3b3eeb094d0d2e8a09d5ee0f5c0b1f5a gvisor-tap-vsock-debuginfo-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: 75420eecd5ed56f19253d2133643443d54fda1c5fc04caa4b2ae5a2eebb89f44 gvisor-tap-vsock-debugsource-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: 440777608893af649b63af94f71edd9ecac4b9387a96d45051a7939fb1c554ec gvisor-tap-vsock-gvforwarder-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: bafdcf14ac8ff9691ea28a6582fe473ee995c64f296bb265b3b242d90ef9a240 gvisor-tap-vsock-gvforwarder-debuginfo-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: 5dae9e9e9cb8d6fabb4e3973508a6fe9f3cb6ed12f231b9c8f8ca4cf3dd6dfec Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 SRPM gvisor-tap-vsock-0.8.5-2.el9_6.2.src.rpm SHA-256: cdd00a4410ca5c530371ea57920f6bd0e5d480d26ddb6ae860e48aba1dac03dd ppc64le gvisor-tap-vsock-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: 2d4a2005950035d34708d39b64c57352ade06d6f5cc83fba24d0d0d0e372f85f gvisor-tap-vsock-debuginfo-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: e254c8f0e68d5a671a97242b913af0fa78c476c55e5bd3bc75cb596f7b2648d4 gvisor-tap-vsock-debugsource-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: b59d1d6d1498afbc23ac0c1df97500cca1a65a298234e9ba63155017ed760ff9 gvisor-tap-vsock-gvforwarder-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: 266a5c6f4a9420b8b48caffff7398e4e29facbc59b9d1ce60d7ee7aecc6460b3 gvisor-tap-vsock-gvforwarder-debuginfo-0.8.5-2.el9_6.2.ppc64le.rpm SHA-256: 2830f5ce22c208a32fa5e1a0a109d356a1cf00b89a7002b3ba4f75247f1366c1 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 SRPM gvisor-tap-vsock-0.8.5-2.el9_6.2.src.rpm SHA-256: cdd00a4410ca5c530371ea57920f6bd0e5d480d26ddb6ae860e48aba1dac03dd x86_64 gvisor-tap-vsock-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: 61de4294460fc6cfc020ecb7bb3436cf26aa104183348cafcb58575cd9e2d85e gvisor-tap-vsock-debuginfo-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: cee38b62f155dcfcbef0090d8b6787fce69bfe3b849a6b4256abf3ee62b786bd gvisor-tap-vsock-debugsource-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: 85de8cdfb52f62683b1258a17d68cc37fe03b6082a994d4386f7fac3108bf2d8 gvisor-tap-vsock-gvforwarder-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: c97adb18dca5bf25440cc3e97351e05939cf801c2d78bd2ffd3f192ee31c90cf gvisor-tap-vsock-gvforwarder-debuginfo-0.8.5-2.el9_6.2.x86_64.rpm SHA-256: d49ea81efce16d8ff0a87c48f2fab996ddac9238c80337f831605f3d5e21f42b Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 SRPM gvisor-tap-vsock-0.8.5-2.el9_6.2.src.rpm SHA-256: cdd00a4410ca5c530371ea57920f6bd0e5d480d26ddb6ae860e48aba1dac03dd aarch64 gvisor-tap-vsock-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: 2e7c70e010cd4f3b767a8f97d4fb4e4d3b3eeb094d0d2e8a09d5ee0f5c0b1f5a gvisor-tap-vsock-debuginfo-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: 75420eecd5ed56f19253d2133643443d54fda1c5fc04caa4b2ae5a2eebb89f44 gvisor-tap-vsock-debugsource-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: 440777608893af649b63af94f71edd9ecac4b9387a96d45051a7939fb1c554ec gvisor-tap-vsock-gvforwarder-0.8.5-2.el9_6.2.aarch64.rpm SHA-256: b

Share this article