A flaw in Go's standard library, tracked as CVE-2026-32282, allows Root.Chmod in internal/syscall/unix to follow a symbolic link outside the intended root on Linux because of a time-of-check/time-of-use race. Red Hat said a local attacker who can create symlinks and win the race could cause permission changes on the symlink target, potentially bypassing directory restrictions; the company rated the issue Moderate and noted no qualifying mitigation was available.
Red Hat has shipped fixes for the bug as part of broader Go security updates across multiple products, including podman, osbuild-composer, and golang-github-openstack-k8s-operators-os-diff used in Red Hat OpenStack Services on OpenShift and several RHEL 9.2/9.4 channels. The advisories also bundled patches for other Go-related issues affecting components such as crypto/tls, crypto/x509, net/url, net, and Go JOSE, covering denial-of-service conditions, certificate validation weaknesses, memory exhaustion, and incorrect IPv6 parsing.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:47910 for osbuild-composer and released version 101.3-4.el9_4.3 across several RHEL 9.4 channels and architectures. The Important-rated advisory fixes five Go vulnerabilities, including CVE-2026-32282 in internal/syscall/unix.
Red Hat published RHSA-2026:39810 for golang-github-openstack-k8s-operators-os-diff in Red Hat OpenStack Services on OpenShift 18.0, rated Important. The update includes fixes for multiple Go vulnerabilities, including CVE-2026-32282 affecting Root.Chmod symlink handling.
Red Hat published RHSA-2026:25248 for podman, rated Important, and released updated podman 4.4.1-22.el9_2.11 packages for multiple RHEL 9.2 channels and architectures. The advisory fixes several Go-related vulnerabilities, including CVE-2025-61729, CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, CVE-2026-25679, and CVE-2026-34986.
Red Hat's CVE record says Cryostat 4 on RHEL 9 component cryostat/cryostat-storage-rhel9 was listed as fixed in RHSA-2026:14391. This extended remediation for the Go Root.Chmod issue to another downstream product.
Red Hat published a CVE page describing CVE-2026-32282 as a moderate-severity flaw in Go's internal/syscall/unix package. The page explains the TOCTOU race condition, notes there is no qualifying mitigation, and enumerates affected and fixed products.
Red Hat lists Red Hat Enterprise Linux 10 grafana in RHSA-2026:11712 and rhc-worker-playbook in RHSA-2026:11863 as fixed for CVE-2026-32282. Both fixes are recorded on the same day in the CVE entry.
Red Hat lists Red Hat Enterprise Linux 10 golang as fixed for CVE-2026-32282 in advisory RHSA-2026:10217. This is one of the first product fixes explicitly tied to the Go Root.Chmod vulnerability in the provided references.
Red Hat's CVE page for CVE-2026-32282 was last modified, reflecting updated tracking information for the Go Root.Chmod symlink-following issue. The entry includes severity, exploit conditions, and linked references such as Bugzilla 2456336 and Go issue 78293.
Red Hat's CVE record states that CVE-2026-32282, a TOCTOU race in Go's internal/syscall/unix Root.Chmod that can follow symlinks out of the intended root, was made public. The flaw can let a local attacker cause chmod to affect the symlink target instead of the checked file.
Red Hat lists Red Hat Enterprise Linux 10 yggdrasil as fixed for CVE-2026-32282 in RHSA-2026:17075. The fix is recorded in the CVE entry as another downstream remediation of the Go flaw.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcego.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.