Red Hat Product Errata RHSA-2026:39272 - Security Advisory Issued: 2026-07-14 Updated: 2026-07-14 RHSA-2026:39272 - Security Advisory Overview Updated Packages Synopsis Important: git-lfs security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for git-lfs is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVEs CVE-2026-33811 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 x86_64 git-lfs-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 5093c38079ce664782b4437ad85446b8e7111a03a5c63bcb4ac1c46fece9a0f1 git-lfs-debuginfo-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 1411ad8436b666b93e0c8557658abafdc0767144a9bf754819a7dd2bec4fc828 git-lfs-debugsource-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 0e156f41794294875c12f2518a9450183624774ab441c2e0cee35211ca6d860b Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 x86_64 git-lfs-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 5093c38079ce664782b4437ad85446b8e7111a03a5c63bcb4ac1c46fece9a0f1 git-lfs-debuginfo-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 1411ad8436b666b93e0c8557658abafdc0767144a9bf754819a7dd2bec4fc828 git-lfs-debugsource-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 0e156f41794294875c12f2518a9450183624774ab441c2e0cee35211ca6d860b Red Hat Enterprise Linux for IBM z Systems 10 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 s390x git-lfs-3.7.1-5.el10_2.6.s390x.rpm SHA-256: a72501726f1dfe69fda299a9113d420ebbd2b452d9e57ca30b7a23970209e3b6 git-lfs-debuginfo-3.7.1-5.el10_2.6.s390x.rpm SHA-256: d01ba6cef0c274fd117d5f557c211c8eeda28904ad8d2438914b6b78fdb0d0d5 git-lfs-debugsource-3.7.1-5.el10_2.6.s390x.rpm SHA-256: 11a15cee9b8e9c3988fa374c16f5205925f2529f739fad79f8782ebf721cce78 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 s390x git-lfs-3.7.1-5.el10_2.6.s390x.rpm SHA-256: a72501726f1dfe69fda299a9113d420ebbd2b452d9e57ca30b7a23970209e3b6 git-lfs-debuginfo-3.7.1-5.el10_2.6.s390x.rpm SHA-256: d01ba6cef0c274fd117d5f557c211c8eeda28904ad8d2438914b6b78fdb0d0d5 git-lfs-debugsource-3.7.1-5.el10_2.6.s390x.rpm SHA-256: 11a15cee9b8e9c3988fa374c16f5205925f2529f739fad79f8782ebf721cce78 Red Hat Enterprise Linux for Power, little endian 10 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 ppc64le git-lfs-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: bc11d75368ab76d95c6593075c073bb6469166548e2a86267295605962ec3080 git-lfs-debuginfo-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: c3a20b7d0f317500acda9ca5007f3735ff38702f9405219cb7a49dcf61319d94 git-lfs-debugsource-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: 0ad65685017be651cb36d6b255189e4c08387e58ed3c9568d7b4d29dc674c34b Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 ppc64le git-lfs-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: bc11d75368ab76d95c6593075c073bb6469166548e2a86267295605962ec3080 git-lfs-debuginfo-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: c3a20b7d0f317500acda9ca5007f3735ff38702f9405219cb7a49dcf61319d94 git-lfs-debugsource-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: 0ad65685017be651cb36d6b255189e4c08387e58ed3c9568d7b4d29dc674c34b Red Hat Enterprise Linux for ARM 64 10 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 aarch64 git-lfs-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: f7f90785bc40f23c43faa037a73bf2451464ad41888cd5db756152ae67d7e0af git-lfs-debuginfo-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: 327de349f1638d7a620a8d940a941898fe932c9dcf689731502e87f799ad64cf git-lfs-debugsource-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: 00e17e62ccd06b1a3fe045982777c3c5aa18efdc7c63428a15434b8745522cc3 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 aarch64 git-lfs-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: f7f90785bc40f23c43faa037a73bf2451464ad41888cd5db756152ae67d7e0af git-lfs-debuginfo-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: 327de349f1638d7a620a8d940a941898fe932c9dcf689731502e87f799ad64cf git-lfs-debugsource-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: 00e17e62ccd06b1a3fe045982777c3c5aa18efdc7c63428a15434b8745522cc3 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 aarch64 git-lfs-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: f7f90785bc40f23c43faa037a73bf2451464ad41888cd5db756152ae67d7e0af git-lfs-debuginfo-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: 327de349f1638d7a620a8d940a941898fe932c9dcf689731502e87f799ad64cf git-lfs-debugsource-3.7.1-5.el10_2.6.aarch64.rpm SHA-256: 00e17e62ccd06b1a3fe045982777c3c5aa18efdc7c63428a15434b8745522cc3 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 s390x git-lfs-3.7.1-5.el10_2.6.s390x.rpm SHA-256: a72501726f1dfe69fda299a9113d420ebbd2b452d9e57ca30b7a23970209e3b6 git-lfs-debuginfo-3.7.1-5.el10_2.6.s390x.rpm SHA-256: d01ba6cef0c274fd117d5f557c211c8eeda28904ad8d2438914b6b78fdb0d0d5 git-lfs-debugsource-3.7.1-5.el10_2.6.s390x.rpm SHA-256: 11a15cee9b8e9c3988fa374c16f5205925f2529f739fad79f8782ebf721cce78 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 ppc64le git-lfs-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: bc11d75368ab76d95c6593075c073bb6469166548e2a86267295605962ec3080 git-lfs-debuginfo-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: c3a20b7d0f317500acda9ca5007f3735ff38702f9405219cb7a49dcf61319d94 git-lfs-debugsource-3.7.1-5.el10_2.6.ppc64le.rpm SHA-256: 0ad65685017be651cb36d6b255189e4c08387e58ed3c9568d7b4d29dc674c34b Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 x86_64 git-lfs-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 5093c38079ce664782b4437ad85446b8e7111a03a5c63bcb4ac1c46fece9a0f1 git-lfs-debuginfo-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 1411ad8436b666b93e0c8557658abafdc0767144a9bf754819a7dd2bec4fc828 git-lfs-debugsource-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 0e156f41794294875c12f2518a9450183624774ab441c2e0cee35211ca6d860b Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 x86_64 git-lfs-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 5093c38079ce664782b4437ad85446b8e7111a03a5c63bcb4ac1c46fece9a0f1 git-lfs-debuginfo-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 1411ad8436b666b93e0c8557658abafdc0767144a9bf754819a7dd2bec4fc828 git-lfs-debugsource-3.7.1-5.el10_2.6.x86_64.rpm SHA-256: 0e156f41794294875c12f2518a9450183624774ab441c2e0cee35211ca6d860b Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 SRPM git-lfs-3.7.1-5.el10_2.6.src.rpm SHA-256: ecbfc2c78776b3dbb989a1f7411d512051913854b6107a01aa642fb36322f802 aarch64 git-lfs-3.7.1-5.el10_2.6.aarch64.rpm SHA-256
A Denial of Service vulnerability (CVE-2026-33811, CVSS 7.5 HIGH) exists in the Go net package where an excessively long CNAME response to a LookupCNAME query can cause a crash. The underlying Go versions affected are any version prior to 1.25.10, and versions 1.26.0 through 1.26.2. Red Hat has issued an Important-rated security update for git-lfs on RHEL 10 to address this vulnerability by incorporating the patched Go runtime.