{"id":"CVE-2026-32282","title":"golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)","summary":"A flaw was found in the internal/syscall/unix package in the Go standard library. If the target of the `Root.Chmod` function is replaced with a symbolic link during execution, specifically after `Root.Chmod` checks the target but before ac…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-367","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream (v. 10)","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","cert_manager_operator_for_red_hat_openshift","confidential_compute_attestation","deployment_validation_operator","externaldns_operator","fence_agents_remediation_operator","gatekeeper 3","logging_subsystem_for_red_hat_openshift","logical_volume_manager_storage","machine_deletion_remediation_operator","migration_toolkit_for_applications 8","migration_toolkit_for_containers","mirror_registry_for_red_hat_openshift","mirror_registry_for_red_hat_openshift 2","multiarch_tuning_operator","multicluster_engine_for_kubernetes","multicluster_global_hub","openshift_developer_tools_and_services","openshift_lightspeed","openshift_pipelines","openshift_serverless","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","amq_broker 7","ansible_automation_platform 2","build_of_apache_camel_hawtio 4","build_of_apicurio_registry 2","ceph_storage 5","ceph_storage 6","certification_program_for_red_hat_enterprise_linux 9","connectivity_link 1","enterprise_linux 10","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","jboss_web_server 6","openshift_cluster_manager_cli","openshift_container_platform 4","openshift_data_foundation 4"],"patched":["ansible_automation_platform_2_6_for_rhel 10","rhem_1_1_for_rhel 10","enterprise_linux_server_v_7_els","ansible_automation_platform_2_5_for_rhel 8","openstack_platform 16.2","satellite_6_16_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","cryostat_4_on_rhel 9","rhem_1_0_for_rhel 9","rhem_1_1_for_rhel 9","openstack_platform 17.1","openstack_services_on_openshift 18.0","9base_rhoso_tools_18","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_codeready_linux_builder_eus_v_10_0","enterprise_linux_codeready_linux_builder_v_10","codeready_linux_builder_eus_v_9_6","enterprise_linux_codeready_linux_builder_v_9","cluster_observability_operator 1.5.0","custom_metric_autoscaler 2.19","hawtio_hawtio 4.4.0","logging_subsystem_for_red_hat_openshift 6.2","logging_subsystem_for_red_hat_openshift 6.4","logging_subsystem_for_red_hat_openshift 6.5"],"published":"2026-04-08","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:11:15+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32282.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32282.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32282"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2456336"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-32282"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32282"},{"url":"https://go.dev/cl/763761"},{"url":"https://go.dev/issue/78293"},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"},{"url":"https://pkg.go.dev/vuln/GO-2026-4864"},{"url":"https://access.redhat.com/errata/RHSA-2026:24762"},{"url":"https://access.redhat.com/errata/RHSA-2026:41019"},{"url":"https://access.redhat.com/errata/RHSA-2026:16101"},{"url":"https://access.redhat.com/errata/RHSA-2026:54191"},{"url":"https://access.redhat.com/errata/RHSA-2026:24761"},{"url":"https://access.redhat.com/errata/RHSA-2026:54757"},{"url":"https://access.redhat.com/errata/RHSA-2026:27076"},{"url":"https://access.redhat.com/errata/RHSA-2026:14391"},{"url":"https://access.redhat.com/errata/RHSA-2026:36796"},{"url":"https://access.redhat.com/errata/RHSA-2026:66401"},{"url":"https://access.redhat.com/errata/RHSA-2026:28046"},{"url":"https://access.redhat.com/errata/RHSA-2026:28047"},{"url":"https://access.redhat.com/errata/RHSA-2026:39810"},{"url":"https://access.redhat.com/errata/RHSA-2026:34366"},{"url":"https://access.redhat.com/errata/RHSA-2026:28385"},{"url":"https://access.redhat.com/errata/RHSA-2026:34368"},{"url":"https://access.redhat.com/errata/RHSA-2026:22326"},{"url":"https://access.redhat.com/errata/RHSA-2026:34365"},{"url":"https://access.redhat.com/errata/RHSA-2026:19715"},{"url":"https://access.redhat.com/errata/RHSA-2026:16024"},{"url":"https://access.redhat.com/errata/RHSA-2026:19550"},{"url":"https://access.redhat.com/errata/RHSA-2026:18032"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00292,"epssPercentile":0.21995,"aliases":["GO-2026-4864","BIT-golang-2026-32282"],"ecosystem":"go","ingestedAt":"2026-07-09T18:56:37.026Z","slug":"CVE-2026-32282","body":"## Overview\n\nA flaw was found in the internal/syscall/unix package in the Go standard library. If the target of the `Root.Chmod` function is replaced with a symbolic link during execution, specifically after `Root.Chmod` checks the target but before acting, the `chmod` operation will be performed on the file the symbolic link points to. This issue can bypass directory restrictions and lead to unauthorized permission changes on the filesystem.\n\n## Vendor advisories\n\n- **RHSA-2026:24762** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24762)\n- **RHSA-2026:41019** · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41019)\n- **RHSA-2026:16101** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16101)\n- **RHSA-2026:54191** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54191)\n- **RHSA-2026:24761** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24761)\n- **RHSA-2026:54757** · Red Hat · fixed in: Red Hat OpenStack Platform 16.2 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54757)\n- **RHSA-2026:27076** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-06-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:27076)\n- **RHSA-2026:14391** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-05-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:14391)\n- **RHSA-2026:36796** · Red Hat · fixed in: RHEM 1.0 for RHEL 9 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36796)\n- **RHSA-2026:66401** · Red Hat · fixed in: Red Hat OpenStack Platform 17.1 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66401)\n- **RHSA-2026:28046** · Red Hat · fixed in: Red Hat OpenStack Platform 17.1 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:28046)\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, cert-manager Operator for Red Hat OpenShift, Confidential Compute Attestation, Deployment Validation Operator, ExternalDNS Operator, Fence Agents Remediation Operator, … · no fix planned: mirror registry for Red Hat OpenShift, Confidential Compute Attestation, Gatekeeper 3, Migration Toolkit for Applications 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32282.json)\n- **RHSA-2026:28047** · Red Hat · fixed in: Red Hat OpenStack Platform 17.1 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:28047)\n\n**golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root** — rated Moderate by Red Hat. Released 2026-04-08, updated 2026-09-21.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- cert-manager Operator for Red Hat OpenShift\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- ExternalDNS Operator\n- Fence Agents Remediation Operator\n- Gatekeeper 3\n- Logging Subsystem for Red Hat OpenShift\n- Logical Volume Manager Storage\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Applications 8\n- Migration Toolkit for Containers\n- mirror registry for Red Hat OpenShift\n- mirror registry for Red Hat OpenShift 2\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Multicluster Global Hub\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apicurio Registry 2\n- Red Hat Ceph Storage 5\n- Red Hat Ceph Storage 6\n- Red Hat Certification Program for Red Hat Enterprise Linux 9\n- Red Hat Connectivity Link 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Web Server 6\n- Red Hat OpenShift Cluster Manager CLI\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n\nFixed:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- RHEM 1.1 for RHEL 10\n- Red Hat Enterprise Linux Server (v. 7 ELS)\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6.16 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Cryostat 4 on RHEL 9\n- RHEM 1.0 for RHEL 9\n- RHEM 1.1 for RHEL 9\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Services on OpenShift 18.0\n- 9Base-RHOSO-TOOLS-18\n- Red Hat Satellite 6.16 for RHEL 9\n- Red Hat Satellite 6.17 for RHEL 9\n- Red Hat Satellite 6.18 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream AUS (v.8.6)\n- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)\n- Red Hat Enterprise Linux AppStream E4S (v.8.8)\n- Red Hat Enterprise Linux AppStream TUS (v.8.8)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream E4S (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)\n- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)\n- Red Hat CodeReady Linux Builder EUS (v.9.6)\n- Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)\n- Cluster Observability Operator 1.5.0\n- Custom Metric Autoscaler 2.19\n- HawtIO HawtIO 4.4.0\n- Logging Subsystem for Red Hat OpenShift 6.2\n- Logging Subsystem for Red Hat OpenShift 6.4\n- Logging Subsystem for Red Hat OpenShift 6.5\n\nNo fix planned:\n\n- mirror registry for Red Hat OpenShift\n- Confidential Compute Attestation\n- Gatekeeper 3\n- Migration Toolkit for Applications 8\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat build of Apicurio Registry 2\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Red Hat Service Interconnect 1\n- Red Hat Service Interconnect 2\n- Zero Trust Workload Identity Manager - Tech Preview\n- Red Hat Ceph Storage 5\n- Red Hat Ceph Storage 6\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- cert-manager Operator for Red Hat OpenShift\n- Deployment Validation Operator\n- ExternalDNS Operator\n- Fence Agents Remediation Operator\n- Logging Subsystem for Red Hat OpenShift\n- Logical Volume Manager Storage\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Containers\n- mirror registry for Red Hat OpenShift 2\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Multicluster Global Hub\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat Certification Program for Red Hat Enterprise Linux 9\n- Red Hat Connectivity Link 1\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- RHEM 1.1 for RHEL 10\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6.16 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Cryostat 4 on RHEL 9\n- RHEM 1.0 for RHEL 9\n- RHEM 1.1 for RHEL 9\n\n## Remediation\n\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:24762\nSee the following documentation for details on how to enable Red Hat Edge\nManager and more:\nhttps://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:41019\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:16101\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-32282)\n\nAffected packages:\n\n- `stdlib >= 1.26.0-0, < 1.26.2`\n\nPatched in:\n\n- `stdlib 1.26.2`\n\nSource: https://osv.dev/vulnerability/GO-2026-4864","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":5085,"id":"CVE-2026-32282","ts":1788887248012,"field":"cvss","old":null,"new":"7.8"},{"seq":5084,"id":"CVE-2026-32282","ts":1788887248012,"field":"severity","old":"none","new":"high"},{"seq":3968,"id":"CVE-2026-32282","ts":1788886363652,"field":"cvss","old":"7.8","new":null},{"seq":3967,"id":"CVE-2026-32282","ts":1788886363652,"field":"severity","old":"high","new":"none"},{"seq":3149,"id":"CVE-2026-32282","ts":1788883133029,"field":"cvss","old":null,"new":"7.8"},{"seq":3148,"id":"CVE-2026-32282","ts":1788883133029,"field":"severity","old":"none","new":"high"}]}