Go disclosed CVE-2026-32283, an Important denial-of-service flaw in crypto/tls that can deadlock TLS 1.3 connections when a peer sends multiple post-handshake key update messages in a single record, leading to uncontrolled resource consumption. Go also disclosed CVE-2026-27144 in cmd/compile, where a no-op interface conversion could bypass overlap checks for memory moves, creating conditions for unsafe overlapping copies and possible memory corruption or unexpected behavior at runtime.
Red Hat subsequently shipped fixes for these Go flaws across multiple RHEL 8, 9, and 10 channels and dependent packages including golang, rhc, ipp-usb, gvisor-tap-vsock, and Cryostat 4, often alongside other Go vulnerabilities in crypto/x509 and internal/syscall/unix. Advisories rated the updates Important, with CVE-2026-32283 scored CVSS 7.5 by Red Hat, and updated package builds were released for major architectures including x86_64, aarch64, ppc64le, and s390x across standard, EUS, AUS, SAP, and Extended Life Cycle offerings.

See real exploitation activity before you spend the cycle.
22 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:49600 on August 3, 2026 for rhc on RHEL 9.2 channels, releasing rhc 0.2.2-1.el9_2.3. The advisory fixed CVE-2026-32283 together with CVE-2025-68121, CVE-2026-32281, CVE-2026-32282, and CVE-2026-32280.
Red Hat published RHSA-2026:47712 on July 29, 2026 for golang packages in RHEL 9.4 channels, updating Go to 1.25.9+2 [rhel-9.4.z]. The advisory fixed CVE-2026-27144, CVE-2026-32283, and several other Go vulnerabilities.
Red Hat published RHSA-2026:28038 on June 22, 2026 for gvisor-tap-vsock on RHEL 9.6 Extended Update Support. The update released version 0.8.5-2.el9_6.2 and fixed CVE-2026-32283, CVE-2026-32282, CVE-2026-32280, and CVE-2026-27137.
Red Hat published RHSA-2026:24337 on June 8, 2026 for rhc on RHEL 9.6 Extended Update Support. The update released rhc 0.2.7-1.el9_6.4 and fixed CVE-2026-32283 along with CVE-2026-32281, CVE-2026-32282, and CVE-2026-32280.
Red Hat published RHSA-2026:22713 on June 3, 2026 for rhc on RHEL 10.0, releasing rhc 0.3.2-4.el10_0. The advisory explicitly fixed CVE-2026-32283 and CVE-2026-32280.
Red Hat published RHSA-2026:19550 on May 20, 2026 for golang-github-openprinting-ipp-usb in RHEL 10.0 channels. The update released ipp-usb 0.9.27-3.el10_0.4 and fixed CVE-2026-32283, CVE-2026-32282, and CVE-2026-32280.
Red Hat published RHSA-2026:19369 on May 19, 2026 for rhc on RHEL 9, releasing rhc 0.2.7-6.el9_8. The advisory fixed CVE-2026-32283 and CVE-2026-32282 for multiple RHEL 9 variants.
Red Hat published RHSA-2026:19156 on May 19, 2026 for rhc on RHEL 10, releasing rhc 0.3.8-4.el10_2. The advisory fixed CVE-2026-32283 and CVE-2026-32282 across multiple RHEL 10 architectures and support channels.
Red Hat published RHSA-2026:19144 on May 19, 2026 for golang-github-openprinting-ipp-usb on RHEL 10, releasing ipp-usb 0.9.27-7.el10_2. The update fixed CVE-2026-32283 together with CVE-2026-33810, CVE-2026-32282, and CVE-2026-32280.
Red Hat published RHSA-2026:17084 on May 13, 2026 for gvisor-tap-vsock on RHEL 10.0. The update shipped version 0.8.5-2.el10_0.1 and fixed CVE-2026-32283, CVE-2026-32282, CVE-2026-32280, and additional Go vulnerabilities.
Red Hat published RHSA-2026:15980 on May 11, 2026 for rhc on RHEL 8. The update released rhc 0.2.5-7.el8_10 and fixed CVE-2026-32283 along with CVE-2026-32282 and CVE-2026-32280.
Red Hat published RHSA-2026:16024 on May 11, 2026 for golang packages on RHEL 10.0, shipping golang 1.25.9-1.el10_0 and fixing CVE-2026-32283, CVE-2026-32282, CVE-2026-32280, CVE-2026-27144, and other Go vulnerabilities.
Red Hat published its CVE page for CVE-2026-32283 on May 6, 2026, rating the issue Important with a CVSS 7.5 score. The entry describes a crypto/tls TLS 1.3 denial-of-service flaw caused by multiple key update messages in a single record.
Red Hat published RHSA-2026:14391 on May 6, 2026 for the Red Hat build of Cryostat 4 on RHEL 9. The advisory fixed CVE-2026-32283 in Go crypto/tls along with several other Go vulnerabilities.
Red Hat published its CVE page for CVE-2026-27144 on April 23, 2026. The entry rated the issue Moderate and documented exploit conditions, impact, and fixed product mappings.
Red Hat lists RHSA-2026:10217 as fixing CVE-2026-27144 for Red Hat Enterprise Linux 10 golang on April 23, 2026. This was one of the first downstream product fixes referenced for the compiler flaw.
Red Hat recorded CVE-2026-27144 as Bugzilla 2456340 on April 8, 2026, classifying it with medium severity and priority. The bug tracks the Go compiler overlap-check bypass issue across affected Red Hat products.
Red Hat marked CVE-2026-27144 public on April 8, 2026. Its advisory describes a cmd/compile flaw where a no-op interface conversion can bypass overlap checking and potentially cause data corruption, memory corruption, or unexpected behavior.
Go opened private issue 78371 on March 25, 2026 for CVE-2026-27144, reported by Jakub Ciolek. The compiler bug failed to unwrap pointers inside a no-op interface conversion, which could misclassify overlapping moves as non-overlapping and allow unsafe move operations.
Go opened private issue 78334 for CVE-2026-32283 on March 24, 2026. The flaw affects TLS 1.3 connections and can deadlock a connection when multiple post-handshake key update messages are sent in a single record, leading to uncontrolled resource consumption and denial of service.
Red Hat lists RHSA-2026:10704 as fixing CVE-2026-27144 for Red Hat Enterprise Linux 8 go-toolset on April 27, 2026. This expanded fixes for the compiler flaw to RHEL 8.
Red Hat lists RHSA-2026:10219 as fixing CVE-2026-27144 for Red Hat Enterprise Linux 9 golang on April 24, 2026. The erratum extended downstream coverage of the Go compiler flaw to RHEL 9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
18 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcego.dev
Open sourcego.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.