Security update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21
This update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21 fixes the following issues: Changes in go compilers: - Switch from update-alternatives to new method. - Packaging improvements: * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install of a working go command. Refs boo#1245878 bsc#1264395 * Based on feedback from Factory maintainers restore the original lifecycle for these files: Each go1.x toolchain shares ownership of a go and gofmt symlink managed by the alternatives system (update-alternatives and libalternatives). When the last go1.x package is uninstalled the symlinks will be removed. * Context: %ghost was introduced to prevent file conflicts among go1.x toolchain packages reported by installcheck dev tool. %ghost prevents the files from being installed, which results in no installed go command. The shared ownership of the go and gofmt symlinks is intentional. * Define go_bootstrap_version with digits without go1.x prefix. Correct path spelling to align with current toolchain layout GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version}, Noting interstitial /go/ in path. Fixes bootstrap ERROR: Cannot find /usr/lib64/go1.x/bin/go. Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y. Bootstrap error first observed when using %ghost /usr/bin/go. Fixed by Eugenio Paolantonio. Refs boo#1245878 bsc#1264395 * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts among go1.x toolchain packages. These files are managed by the alternatives system. Refs boo#1245878 bsc#1264395
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21 fixes the following issues: Changes in go compilers: - Switch from update-alternatives to new method. - Packaging improvements: * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install of a working go command. Refs boo#1245878 bsc#1264395 * Based on feedback from Factory maintainers restore the original lifecycle for these files: Each go1.x toolchain shares ownership of a go and gofmt symlink managed by the alternatives system (update-alternatives and libalternatives). When the last go1.x package is uninstalled the symlinks will be removed. * Context: %ghost was introduced to prevent file conflicts among go1.x toolchain packages reported by installcheck dev tool. %ghost prevents the files from being installed, which results in no installed go command. The shared ownership of the go and gofmt symlinks is intentional. * Define go_bootstrap_version with digits without go1.x prefix. Correct path spelling to align with current toolchain layout GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version}, Noting interstitial /go/ in path. Fixes bootstrap ERROR: Cannot find /usr/lib64/go1.x/bin/go. Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y. Bootstrap error first observed when using %ghost /usr/bin/go. Fixed by Eugenio Paolantonio. Refs boo#1245878 bsc#1264395 * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts among go1.x toolchain packages. These files are managed by the alternatives system. Refs boo#1245878 bsc#1264395
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1245878
- https://bugzilla.suse.com/1264390
- https://bugzilla.suse.com/1264391
- https://bugzilla.suse.com/1264392
- https://bugzilla.suse.com/1264393
- https://bugzilla.suse.com/1264394
- https://bugzilla.suse.com/1264395
- https://www.suse.com/security/cve/CVE-2025-22871
- https://www.suse.com/support/update/announcement/2026/suse-su-202622950-1/