Double free in Go programming language - CVE-2026-33811
Published: July 31, 2026
Vulnerability identifier: #VU140611
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2026-33811
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to double free in net.LookupCNAME and Resolver.LookupCNAME when processing a very long CNAME response with the cgo DNS resolver. A remote attacker can send a specially crafted DNS response to cause a denial of service.
Affected software
Go programming language
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
rhc-worker-playbook (Red Hat package)
golang-github-openprinting-ipp-usb (Red Hat package)
oci-seccomp-bpf-hook (Red Hat package)
golang
golang-bin
golang-shared
golang-docs
golang-misc
golang-src
golang-tests
git-lfs (Red Hat package)
git-lfs
git-lfs-doc
Red Hat OpenShift GitOps
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
rhc-worker-playbook (Red Hat package)
golang-github-openprinting-ipp-usb (Red Hat package)
oci-seccomp-bpf-hook (Red Hat package)
golang
golang-bin
golang-shared
golang-docs
golang-misc
golang-src
golang-tests
git-lfs (Red Hat package)
git-lfs
git-lfs-doc
Red Hat OpenShift GitOps
How to mitigate CVE-2026-33811
Install security update from vendor's website.
Go programming language - addressed in versions 1.25.10, 1.26.3
rhc-worker-playbook (Red Hat package) - update to 0.2.10-1.el10_2
golang-github-openprinting-ipp-usb (Red Hat package) - update to 0.9.27-7.el10_2.2
oci-seccomp-bpf-hook (Red Hat package) - update to 1.2.11-2.el9_8
Red Hat OpenShift GitOps - update to 1.21.1
golang - update to 1.25.9-5
golang-bin - update to 1.25.9-5
golang-shared - update to 1.25.9-5
golang-docs - update to 1.25.9-5
golang-misc - update to 1.25.9-5
golang-src - update to 1.25.9-5
golang-tests - update to 1.25.9-5
git-lfs (Red Hat package) - addressed in versions 3.4.1-12.el8_10, 3.7.1-4.el9_8.2, 3.7.1-5.el10_2.6
git-lfs - update to 3.4.1-12.0.1
git-lfs-doc - update to 3.4.1-12.0.1
rhc-worker-playbook (Red Hat package) - update to 0.2.10-1.el10_2
golang-github-openprinting-ipp-usb (Red Hat package) - update to 0.9.27-7.el10_2.2
oci-seccomp-bpf-hook (Red Hat package) - update to 1.2.11-2.el9_8
Red Hat OpenShift GitOps - update to 1.21.1
golang - update to 1.25.9-5
golang-bin - update to 1.25.9-5
golang-shared - update to 1.25.9-5
golang-docs - update to 1.25.9-5
golang-misc - update to 1.25.9-5
golang-src - update to 1.25.9-5
golang-tests - update to 1.25.9-5
git-lfs (Red Hat package) - addressed in versions 3.4.1-12.el8_10, 3.7.1-4.el9_8.2, 3.7.1-5.el10_2.6
git-lfs - update to 3.4.1-12.0.1
git-lfs-doc - update to 3.4.1-12.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Go programming language
- Red Hat Enterprise Linux 10 update for golang-github-openprinting-ipp-usb
- Double free in Red Hat OpenShift GitOps 1.21
- Red Hat Enterprise Linux 9 update for oci-seccomp-bpf-hook
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 10 update for git-lfs
- Red Hat Enterprise Linux 9 update for git-lfs
- Red Hat Enterprise Linux 10 update for rhc-worker-playbook
- Anolis OS update for golang
- Anolis OS update for git-lfs