mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
go1.26.2 (released 2026-04-07) includes security fixes to the go command, the compiler, and the archive/tar, crypto/tls, crypto/x509, html/template, and os packages, as well as bug fixes to the go command, the go fix command, the compiler, the linker, the runtime, and the net, net/http, and net/url packages. CVE-2026-32289: html/template: JS template literal context incorrectly tracked CVE-2026-33810: crypto/x509: excluded DNS constraints not properly applied to wildcard domains CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG CVE-2026-32280: crypto/x509: unexpected work during chain building CVE-2026-32281: crypto/x509: inefficient policy validation https://go.dev/doc/devel/release#go1.26.2 https://github.com/golang/go/issues?q=milestone%3AGo1.26.2+label%3ACherryPickApproved Signed-off-by: Christian Stewart <christian@aperture.us> [Julien: add "security" in commit log title] Signed-off-by: Julien Olivain <ju.o@free.fr>