Red Hat Product Errata RHSA-2026:46394 - Security Advisory Issued: 2026-07-27 Updated: 2026-07-27 RHSA-2026:46394 - Security Advisory Overview Updated Packages Synopsis Important: go-fdo-client security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for go-fdo-client is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description go-fdo-client is the device-side implementation of FIDO Device Onboard specification in Go. It provides an FDO client that interacts with FDO manufacturer and owner servers to perform device on-boarding. Security Fix(es): crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Fixes BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVEs CVE-2026-27145 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM go-fdo-client-1.0.0-4.el10_2.5.src.rpm SHA-256: 7dac3db6d2ca8a5f817f8de0e436bd3a47f3360b779c63aeaf974411ce25c60b x86_64 go-fdo-client-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 09b443c7faef6c5a30226fefebaab0e0f5c3e6e69e72654a850ada11bb8eb1c1 go-fdo-client-debuginfo-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 08e3aaae24805b09f7583e44e2d5f4759a192348516ae47524c3305a5ac37526 go-fdo-client-debugsource-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 4a014480796253739c36770a12f950c88e17819685f6a247ee9bbd3b4340fa93 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM go-fdo-client-1.0.0-4.el10_2.5.src.rpm SHA-256: 7dac3db6d2ca8a5f817f8de0e436bd3a47f3360b779c63aeaf974411ce25c60b x86_64 go-fdo-client-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 09b443c7faef6c5a30226fefebaab0e0f5c3e6e69e72654a850ada11bb8eb1c1 go-fdo-client-debuginfo-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 08e3aaae24805b09f7583e44e2d5f4759a192348516ae47524c3305a5ac37526 go-fdo-client-debugsource-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 4a014480796253739c36770a12f950c88e17819685f6a247ee9bbd3b4340fa93 Red Hat Enterprise Linux for ARM 64 10 SRPM go-fdo-client-1.0.0-4.el10_2.5.src.rpm SHA-256: 7dac3db6d2ca8a5f817f8de0e436bd3a47f3360b779c63aeaf974411ce25c60b aarch64 go-fdo-client-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 48f766963b28e2b4b5a2043540829c0edd4fa1f34d8eae3042a63a07a09ecff4 go-fdo-client-debuginfo-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 068d72a7f0d9dca39502046f6394a7f35309b3af2ffc278c580d68a73c0c8bf1 go-fdo-client-debugsource-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 0f5f5ae6129546a606238bf8cc02dd7933b22ea2900410162a695bd3646faa3b Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM go-fdo-client-1.0.0-4.el10_2.5.src.rpm SHA-256: 7dac3db6d2ca8a5f817f8de0e436bd3a47f3360b779c63aeaf974411ce25c60b aarch64 go-fdo-client-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 48f766963b28e2b4b5a2043540829c0edd4fa1f34d8eae3042a63a07a09ecff4 go-fdo-client-debuginfo-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 068d72a7f0d9dca39502046f6394a7f35309b3af2ffc278c580d68a73c0c8bf1 go-fdo-client-debugsource-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 0f5f5ae6129546a606238bf8cc02dd7933b22ea2900410162a695bd3646faa3b Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 SRPM go-fdo-client-1.0.0-4.el10_2.5.src.rpm SHA-256: 7dac3db6d2ca8a5f817f8de0e436bd3a47f3360b779c63aeaf974411ce25c60b aarch64 go-fdo-client-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 48f766963b28e2b4b5a2043540829c0edd4fa1f34d8eae3042a63a07a09ecff4 go-fdo-client-debuginfo-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 068d72a7f0d9dca39502046f6394a7f35309b3af2ffc278c580d68a73c0c8bf1 go-fdo-client-debugsource-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 0f5f5ae6129546a606238bf8cc02dd7933b22ea2900410162a695bd3646faa3b Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 SRPM go-fdo-client-1.0.0-4.el10_2.5.src.rpm SHA-256: 7dac3db6d2ca8a5f817f8de0e436bd3a47f3360b779c63aeaf974411ce25c60b x86_64 go-fdo-client-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 09b443c7faef6c5a30226fefebaab0e0f5c3e6e69e72654a850ada11bb8eb1c1 go-fdo-client-debuginfo-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 08e3aaae24805b09f7583e44e2d5f4759a192348516ae47524c3305a5ac37526 go-fdo-client-debugsource-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 4a014480796253739c36770a12f950c88e17819685f6a247ee9bbd3b4340fa93 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 SRPM go-fdo-client-1.0.0-4.el10_2.5.src.rpm SHA-256: 7dac3db6d2ca8a5f817f8de0e436bd3a47f3360b779c63aeaf974411ce25c60b x86_64 go-fdo-client-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 09b443c7faef6c5a30226fefebaab0e0f5c3e6e69e72654a850ada11bb8eb1c1 go-fdo-client-debuginfo-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 08e3aaae24805b09f7583e44e2d5f4759a192348516ae47524c3305a5ac37526 go-fdo-client-debugsource-1.0.0-4.el10_2.5.x86_64.rpm SHA-256: 4a014480796253739c36770a12f950c88e17819685f6a247ee9bbd3b4340fa93 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 SRPM go-fdo-client-1.0.0-4.el10_2.5.src.rpm SHA-256: 7dac3db6d2ca8a5f817f8de0e436bd3a47f3360b779c63aeaf974411ce25c60b aarch64 go-fdo-client-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 48f766963b28e2b4b5a2043540829c0edd4fa1f34d8eae3042a63a07a09ecff4 go-fdo-client-debuginfo-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 068d72a7f0d9dca39502046f6394a7f35309b3af2ffc278c580d68a73c0c8bf1 go-fdo-client-debugsource-1.0.0-4.el10_2.5.aarch64.rpm SHA-256: 0f5f5ae6129546a606238bf8cc02dd7933b22ea2900410162a695bd3646faa3b The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A Denial of Service vulnerability (CVE-2026-27145, CVSS 6.5) exists in the `crypto/x509` library of the Go programming language, where excessive processing of DNS SAN entries in X.509 certificates can lead to resource exhaustion. This vulnerability impacts the `go-fdo-client` package used for FIDO Device Onboard in Red Hat Enterprise Linux 10. The flaw is addressed by updating to the patched `go-fdo-client` packages provided in the security advisory, specifically version `1.0.0-4.el10_2.5` for the affected RHEL 10.2 streams.