Описание
ELSA-2026-38494: buildah security update (IMPORTANT)
[1.43.1-4.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]
[2:1.43.1-4]
- rebuild for CVE-2026-39822
- Resolves: RHEL-193643
[2:1.43.1-3]
- bump golang.org/x/crypto to v0.52.0 to fix CVE-2026-39830
- Resolves: RHEL-186266
[2:1.43.1-2]
- Rebuild for CVE-2026-25679
- Resolves: RHEL-158476
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
buildah
1.43.1-4.0.1.el10_2
buildah-tests
1.43.1-4.0.1.el10_2
Oracle Linux x86_64
buildah
1.43.1-4.0.1.el10_2
buildah-tests
1.43.1-4.0.1.el10_2
Связанные CVE
Связанные уязвимости
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
On Unix systems, opening a file in an os.Root improperly follows symli ...