Red Hat Security Advisory: git-lfs security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🎯 Affected products14
- Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-0:3.7.1-5.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-0:3.7.1-5.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-0:3.7.1-5.el10_2.6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-0:3.7.1-5.el10_2.6.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-0:3.7.1-5.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-debuginfo-0:3.7.1-5.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-debuginfo-0:3.7.1-5.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-debuginfo-0:3.7.1-5.el10_2.6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-debuginfo-0:3.7.1-5.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-debugsource-0:3.7.1-5.el10_2.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-debugsource-0:3.7.1-5.el10_2.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-debugsource-0:3.7.1-5.el10_2.6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- git-lfs-debugsource-0:3.7.1-5.el10_2.6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment.