USN-8883-1: Go vulnerability
Publication date
6 October 2026
Overview
Go could allow unintended access to network services.
Releases
Packages
- golang-1.18 - Go programming language compiler
- golang-1.21 - Go programming language compiler
- golang-1.24 - Go programming language compiler
Details
It was discovered that the Go x/net/idna package incorrectly handled
certain Punycode-encoded labels that decoded to ASCII-only labels. An
attacker could possibly use this issue to bypass hostname-based access
controls and escalate privileges.
It was discovered that the Go x/net/idna package incorrectly handled
certain Punycode-encoded labels that decoded to ASCII-only labels. An
attacker could possibly use this issue to bypass hostname-based access
controls and escalate privileges.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 22.04 LTS jammy | golang-1.18 – 1.18.1-1ubuntu1.3 | ||
| golang-1.18-go – 1.18.1-1ubuntu1.3 | |||
| golang-1.18-src – 1.18.1-1ubuntu1.3 | |||
| golang-1.21 – 1.21.1-1~ubuntu22.04.4 | |||
| golang-1.21-go – 1.21.1-1~ubuntu22.04.4 | |||
| golang-1.21-src – 1.21.1-1~ubuntu22.04.4 | |||
| golang-1.24 – 1.24.13-2~22.04.2 | |||
| golang-1.24-go – 1.24.13-2~22.04.2 | |||
| golang-1.24-src – 1.24.13-2~22.04.2 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.