RHSA-2026:39266HighCVSS 7.5

Red Hat Security Advisory: git-lfs security update

Published
July 14, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME

🎯 Affected products14

  • Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-0:3.4.1-12.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-0:3.4.1-12.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-0:3.4.1-12.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-0:3.4.1-12.el8_10.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-0:3.4.1-12.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-debuginfo-0:3.4.1-12.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-debuginfo-0:3.4.1-12.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-debuginfo-0:3.4.1-12.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-debuginfo-0:3.4.1-12.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-debugsource-0:3.4.1-12.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-debugsource-0:3.4.1-12.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-debugsource-0:3.4.1-12.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • git-lfs-debugsource-0:3.4.1-12.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment.

🔗 References (4)