Bug 2484205 (CVE-2026-42507)

Summary: CVE-2026-42507 net/textproto: golang: Golang net/textproto: Misleading error messages via input injection
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, akhatavk, akostadi, akoudelk, alcohan, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, aos-team-art-private, aruklets, asatyam, asdas, bbrownin, bdettelb, bniver, chfoley, ckandaga, cmah, crizzo, dakwon, dhanak, diagrawa, dkeler, dmayorov, doconnor, dpaolell, drosa, dschmidt, dsimansk, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, erezende, ewittman, fdeutsch, flucifre, gbenhaim, ggainey, gmeno, gparvin, groman, hasun, ibolton, jaharrin, janstey, jbalunas, jbritton, jburrell, jcantril, jchui, jdelft, jeder, jfula, jhe, jjoyce, jkoehler, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jpretori, jschluet, jtolenti, jupierce, juwatts, kingland, kshier, ktsao, kverlaen, lball, lbragsta, lchilton, lgamliel, lgarciaa, lhh, lphiri, lwan, manissin, mbenjamin, mbiarnes, mbocek, mburns, mdellweg, mgarciac, mhackett, mhess, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, nipatil, niyer, nmoumoul, nyancey, oaljalju, ometelka, oramraz, osousa, pahickey, pantinor, pcreech, peholase, pgaikwad, pjindal, ppalepu, ppostler, prdhamdh, psrna, ptisnovs, pvasanth, rchan, rekumar, rfreiman, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rojacob, sabiswas, sakbas, sausingh, sbratsla, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, smallamp, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, suppawar, swoodman, syedriko, teagle, thason, tmalecek, tsedmik, twaugh, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, vlaad, vle, vvoronko, vwilson, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, xiyuan, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the net/textproto package in Golang. When functions in this package return errors, they include their input as part of the error message. An attacker could exploit this by injecting misleading content into these error messages, which are then printed or logged. This could lead to confusion or misinterpretation of critical system information.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-06-02 23:01:25 UTC
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

Comment 2 errata-xmlrpc 2026-06-25 16:02:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:29980 https://access.redhat.com/errata/RHSA-2026:29980

Comment 3 errata-xmlrpc 2026-06-25 17:18:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:29981 https://access.redhat.com/errata/RHSA-2026:29981

Comment 4 errata-xmlrpc 2026-08-03 15:59:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:49702 https://access.redhat.com/errata/RHSA-2026:49702

Comment 5 errata-xmlrpc 2026-08-03 17:34:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:49712 https://access.redhat.com/errata/RHSA-2026:49712

Comment 7 errata-xmlrpc 2026-08-20 18:47:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:57649 https://access.redhat.com/errata/RHSA-2026:57649

Comment 8 errata-xmlrpc 2026-08-31 04:06:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:61253 https://access.redhat.com/errata/RHSA-2026:61253