Red Hat Product Errata RHSA-2026:39266 - Security Advisory Issued: 2026-07-14 Updated: 2026-07-14 RHSA-2026:39266 - Security Advisory Overview Updated Packages Synopsis Important: git-lfs security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for git-lfs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVEs CVE-2026-33811 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM git-lfs-3.4.1-12.el8_10.src.rpm SHA-256: e196e5724d2408b81c0bdfb8444faaa49be1e9bd22d83ff750e636437ba61c87 x86_64 git-lfs-3.4.1-12.el8_10.x86_64.rpm SHA-256: dd82b7e39c180e8268fa7c273dbb7dd5d2d170259b550453f06d421d7588414b git-lfs-debuginfo-3.4.1-12.el8_10.x86_64.rpm SHA-256: f8fef6d94ea66c6efb1e45c190f815d9ad7d432a5a4f528e58e14652a2cc8487 git-lfs-debugsource-3.4.1-12.el8_10.x86_64.rpm SHA-256: 7c83fa49529eb10a163595cdfbd0adb406c805fb76bb9caa3c85512aed337ed6 Red Hat Enterprise Linux for IBM z Systems 8 SRPM git-lfs-3.4.1-12.el8_10.src.rpm SHA-256: e196e5724d2408b81c0bdfb8444faaa49be1e9bd22d83ff750e636437ba61c87 s390x git-lfs-3.4.1-12.el8_10.s390x.rpm SHA-256: ef507b6ce78baa8dbbf6e696f55ec5168eb0c731d77345da88a7a45b7dac591b git-lfs-debuginfo-3.4.1-12.el8_10.s390x.rpm SHA-256: dc7f9346bc941b1d6a4b2d9b7adc9e754b13c4ec0ed309d9f33932de2265d5cc git-lfs-debugsource-3.4.1-12.el8_10.s390x.rpm SHA-256: 72e316f89b729d5698fcd23a17766244ae33c2ec29381e987872145e1efd44ec Red Hat Enterprise Linux for Power, little endian 8 SRPM git-lfs-3.4.1-12.el8_10.src.rpm SHA-256: e196e5724d2408b81c0bdfb8444faaa49be1e9bd22d83ff750e636437ba61c87 ppc64le git-lfs-3.4.1-12.el8_10.ppc64le.rpm SHA-256: 1e16c87e940e08519548f98ff8805a09ccdbc1f9d6891c891821be131f493eea git-lfs-debuginfo-3.4.1-12.el8_10.ppc64le.rpm SHA-256: 3fc3751fe62304302d24b7a4a9e227aeca96178da975ca0f4e9b061ff1ba6ba7 git-lfs-debugsource-3.4.1-12.el8_10.ppc64le.rpm SHA-256: 3fcb93cd36fcde3c480e43d88b29f7592193779fea299c0861c044d3da931e11 Red Hat Enterprise Linux for ARM 64 8 SRPM git-lfs-3.4.1-12.el8_10.src.rpm SHA-256: e196e5724d2408b81c0bdfb8444faaa49be1e9bd22d83ff750e636437ba61c87 aarch64 git-lfs-3.4.1-12.el8_10.aarch64.rpm SHA-256: 2ac0e8e8905a0d5e59a63eed1510cbe44dbc1f1d46c762993abe62f3cdb0026a git-lfs-debuginfo-3.4.1-12.el8_10.aarch64.rpm SHA-256: 70125c8861f34259b0bcec5526819926f95d93bffc73f35a6d8e50ddad3a0506 git-lfs-debugsource-3.4.1-12.el8_10.aarch64.rpm SHA-256: 2f176d44020fd3f0397e3fe14fd52fde6a89622b320c100937fa89f2f5f16d16 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM git-lfs-3.4.1-12.el8_10.src.rpm SHA-256: e196e5724d2408b81c0bdfb8444faaa49be1e9bd22d83ff750e636437ba61c87 x86_64 git-lfs-3.4.1-12.el8_10.x86_64.rpm SHA-256: dd82b7e39c180e8268fa7c273dbb7dd5d2d170259b550453f06d421d7588414b git-lfs-debuginfo-3.4.1-12.el8_10.x86_64.rpm SHA-256: f8fef6d94ea66c6efb1e45c190f815d9ad7d432a5a4f528e58e14652a2cc8487 git-lfs-debugsource-3.4.1-12.el8_10.x86_64.rpm SHA-256: 7c83fa49529eb10a163595cdfbd0adb406c805fb76bb9caa3c85512aed337ed6 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM git-lfs-3.4.1-12.el8_10.src.rpm SHA-256: e196e5724d2408b81c0bdfb8444faaa49be1e9bd22d83ff750e636437ba61c87 aarch64 git-lfs-3.4.1-12.el8_10.aarch64.rpm SHA-256: 2ac0e8e8905a0d5e59a63eed1510cbe44dbc1f1d46c762993abe62f3cdb0026a git-lfs-debuginfo-3.4.1-12.el8_10.aarch64.rpm SHA-256: 70125c8861f34259b0bcec5526819926f95d93bffc73f35a6d8e50ddad3a0506 git-lfs-debugsource-3.4.1-12.el8_10.aarch64.rpm SHA-256: 2f176d44020fd3f0397e3fe14fd52fde6a89622b320c100937fa89f2f5f16d16 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM git-lfs-3.4.1-12.el8_10.src.rpm SHA-256: e196e5724d2408b81c0bdfb8444faaa49be1e9bd22d83ff750e636437ba61c87 ppc64le git-lfs-3.4.1-12.el8_10.ppc64le.rpm SHA-256: 1e16c87e940e08519548f98ff8805a09ccdbc1f9d6891c891821be131f493eea git-lfs-debuginfo-3.4.1-12.el8_10.ppc64le.rpm SHA-256: 3fc3751fe62304302d24b7a4a9e227aeca96178da975ca0f4e9b061ff1ba6ba7 git-lfs-debugsource-3.4.1-12.el8_10.ppc64le.rpm SHA-256: 3fcb93cd36fcde3c480e43d88b29f7592193779fea299c0861c044d3da931e11 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 SRPM git-lfs-3.4.1-12.el8_10.src.rpm SHA-256: e196e5724d2408b81c0bdfb8444faaa49be1e9bd22d83ff750e636437ba61c87 s390x git-lfs-3.4.1-12.el8_10.s390x.rpm SHA-256: ef507b6ce78baa8dbbf6e696f55ec5168eb0c731d77345da88a7a45b7dac591b git-lfs-debuginfo-3.4.1-12.el8_10.s390x.rpm SHA-256: dc7f9346bc941b1d6a4b2d9b7adc9e754b13c4ec0ed309d9f33932de2265d5cc git-lfs-debugsource-3.4.1-12.el8_10.s390x.rpm SHA-256: 72e316f89b729d5698fcd23a17766244ae33c2ec29381e987872145e1efd44ec The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A Denial of Service (DoS) vulnerability (CVE-2026-33811, CVSS 7.5 High) exists in the Go net package where an excessively long CNAME response to a LookupCNAME call can cause a panic. The vulnerability affects Go versions prior to 1.25.10 and versions 1.26.0 through 1.26.2. The flaw is fixed in Go versions 1.25.10 and 1.26.3, which are included in the updated git-lfs packages for Red Hat Enterprise Linux 8.