RHSA-2026:36617HighCVSS 7.5

Red Hat Security Advisory: oci-seccomp-bpf-hook security update

Published
July 8, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME

🎯 Affected products14

  • Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-0:1.2.11-2.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-0:1.2.11-2.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-0:1.2.11-2.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-0:1.2.11-2.el9_8.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-0:1.2.11-2.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-debuginfo-0:1.2.11-2.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-debuginfo-0:1.2.11-2.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-debuginfo-0:1.2.11-2.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-debuginfo-0:1.2.11-2.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-debugsource-0:1.2.11-2.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-debugsource-0:1.2.11-2.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-debugsource-0:1.2.11-2.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • oci-seccomp-bpf-hook-debugsource-0:1.2.11-2.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment.

🔗 References (4)