REDHAT-BUG-2467822: High severity go Go vulnerability
Published May 7, 2026
·Updated
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
Affected Software
1 affected component
go Go
Event History
May 7, 2026
Data Sourced
via Red Hat·08:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2467822?
The severity of REDHAT-BUG-2467822 is classified as high with a score of 7.
2
What causes the REDHAT-BUG-2467822 vulnerability?
REDHAT-BUG-2467822 is caused by a double-free of C memory triggered by a very long CNAME response when using the LookupCNAME function with the cgo DNS resolver.
3
How can I mitigate REDHAT-BUG-2467822?
To mitigate REDHAT-BUG-2467822, users should avoid using the cgo DNS resolver for LookupCNAME with potentially long CNAME records.
4
What is the impact of REDHAT-BUG-2467822?
The impact of REDHAT-BUG-2467822 is a crash of the application due to memory management errors.
5
When was REDHAT-BUG-2467822 published?
REDHAT-BUG-2467822 was published on May 7, 2026.