Описание
ELSA-2026-19032: buildah security update (IMPORTANT)
[1.43.1-1.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]
[2:1.43.1-1]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.43 (https://github.com/containers/buildah/commit/c6eb14c)
- fixes 'Buildah concurrent bearer token requests [RHEL 10.2] [0day]'
- Resolves: RHEL-164030
[2:1.43.0-3]
- Switch from GnuPG to Sequoia for container image signature verification
- Enable containers_image_sequoia build tag and add podman-sequoia dependency
- Resolves: RHEL-56366
[2:1.43.0-2]
- Rebuild for new golang to address CVE-2025-68121
- Resolves: RHEL-149240
[2:1.43.0-1]
- update to https://github.com/containers/buildah/releases/tag/v1.43.0
- Related: RHEL-122178
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
buildah
1.43.1-1.0.1.el10_2
buildah-tests
1.43.1-1.0.1.el10_2
Oracle Linux x86_64
buildah
1.43.1-1.0.1.el10_2
buildah-tests
1.43.1-1.0.1.el10_2
Связанные CVE
Связанные уязвимости
CVSS3: 7.5
ubuntu
5 месяцев назад
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVSS3: 7.5
redhat
5 месяцев назад
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVSS3: 7.5
nvd
5 месяцев назад
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVSS3: 7.5
debian
5 месяцев назад
url.Parse insufficiently validated the host/authority component and ac ...