Double free in Go programming language - CVE-2026-33811

 

Double free in Go programming language - CVE-2026-33811

Published: July 31, 2026


Vulnerability identifier: #VU140611
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2026-33811
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to double free in net.LookupCNAME and Resolver.LookupCNAME when processing a very long CNAME response with the cgo DNS resolver. A remote attacker can send a specially crafted DNS response to cause a denial of service.


Affected software

Go programming language
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
rhc-worker-playbook (Red Hat package)
golang-github-openprinting-ipp-usb (Red Hat package)
oci-seccomp-bpf-hook (Red Hat package)
golang
golang-bin
golang-shared
golang-docs
golang-misc
golang-src
golang-tests
git-lfs (Red Hat package)
git-lfs
git-lfs-doc
Red Hat OpenShift GitOps

How to mitigate CVE-2026-33811

Install security update from vendor's website.

Go programming language - addressed in versions 1.25.10, 1.26.3
rhc-worker-playbook (Red Hat package) - update to 0.2.10-1.el10_2
golang-github-openprinting-ipp-usb (Red Hat package) - update to 0.9.27-7.el10_2.2
oci-seccomp-bpf-hook (Red Hat package) - update to 1.2.11-2.el9_8
Red Hat OpenShift GitOps - update to 1.21.1
golang - update to 1.25.9-5
golang-bin - update to 1.25.9-5
golang-shared - update to 1.25.9-5
golang-docs - update to 1.25.9-5
golang-misc - update to 1.25.9-5
golang-src - update to 1.25.9-5
golang-tests - update to 1.25.9-5
git-lfs (Red Hat package) - addressed in versions 3.4.1-12.el8_10, 3.7.1-4.el9_8.2, 3.7.1-5.el10_2.6
git-lfs - update to 3.4.1-12.0.1
git-lfs-doc - update to 3.4.1-12.0.1

External References

Related Security Bulletins