-
released this
2026-07-22 08:11:59 +00:00 | -79 commits to c8 since this releaseBackport upstream commit 8c4c965e028475082408749b50ed7a686df0d265
from github.com/golang/net to fix CVE-2026-39821 in the vendored
golang.org/x/net/idna package.The fix causes the idna package to correctly reject xn-- labels
which decode to all-ASCII labels, addressing a specification bug
corrected in UTS 46 revision 33. The patch modifies 13 files in
the vendored idna package, removing obsolete version-specific
files and updating core functionality.CVE: CVE-2026-33811, CVE-2026-39821
Upstream patches:github.com/golang/net@8c4c965e02.patch
Resolves: RHEL-183684, RHEL-187159
This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.
Assisted-by: Ymir
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
1 download