Описание
ELSA-2026-38504: container-tools:ol8 security update (IMPORTANT)
aardvark-dns [2:1.10.1-2]
- build off the RHEL maintenance branch
- Resolves: RHEL-59129
buildah [2:1.33.14-4]
- switch source URL from GitHub to the internal GitLab sustaining-engineering repo
- update to the latest content of release-1.33 (commit 2cbee78)
- bump golang.org/x/crypto to v0.53.0 to fix CVE-2026-39829, CVE-2026-39830, CVE-2026-39832
cockpit-podman [84.1-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/84.1
- Related: Jira:RHEL-25557
conmon [3:2.1.10-1]
- update to https://github.com/containers/conmon/releases/tag/v2.1.10
- Related: Jira:RHEL-2110
containernetworking-plugins [1:1.4.0-8]
- rebuild for CVE-2025-68121
- Resolves: RHEL-149265
containers-common [1-82.0.1]
- Updated removed references [Orabug: 33473101] (Alex Burmashev)
- Adjust registries.conf (Nikita Gerasimov)
- remove references to RedHat registry (Nikita Gerasimov)
container-selinux [2:2.229.0-3]
- add user_t confined user container support (cherry-pick of upstream PR #443)
- Resolves: RHEL-135342
criu [3.18-5]
- rebuild to preserve upgrade path
- Related: RHEL-32671
crun [1.14.3-2]
- remove BR libgcrypt-devel, no longer needed
- Related: Jira:RHEL-2110
fuse-overlayfs [1.13-1]
- update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.13
- Related: Jira:RHEL-2110
libslirp [4.4.0-2]
- rebuild to preserve upgrade path 8.9 -> 8.10
- Related: RHEL-32671
netavark [2:1.10.3-1]
- update to https://github.com/containers/netavark/releases/tag/v1.10.3
- Related: Jira:RHEL-2110
oci-seccomp-bpf-hook [1.2.10-1]
- update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.10
- Related: Jira:RHEL-2110
podman [4.9.4-34.0.1]
- Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813]
- Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802]
- Fixes issue of podman execvp error while using podmansh [Orabug: 36756665]
[4:4.9.4-34]
- upload source tarball for v4.9-rhel (commit bd39e82)
- Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553
[4:4.9.4-33]
- update to the latest content of v4.9-rhel (commit bd39e82) to fix CVE-2026-39835, CVE-2026-57231, CVE-2026-25681, CVE-2026-27136
- Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553
python-podman [4.9.0-3]
- sync with release-4.9 branch
- Resolves: RHEL-31069
runc [4:1.2.9-4]
- rebuild for CVE-2025-68121
- Resolves: RHEL-149266
skopeo [2:1.14.6-2]
- Rebuild for CVE-2026-32281
- Resolves: RHEL-177067
slirp4netns [1.2.3-1]
- update to https://github.com/rootless-containers/slirp4netns/releases/tag/v1.2.3
- Related: Jira:RHEL-2110
udica [0.2.6-21]
- bump release to preserve update path
- Resolves: RHEL-32671
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
Module container-tools:ol8 is enabled
aardvark-dns
1.10.1-2.module+el8.10.0+90960+1362bdc4
buildah
1.33.14-4.module+el8.10.0+90960+1362bdc4
buildah-tests
1.33.14-4.module+el8.10.0+90960+1362bdc4
cockpit-podman
84.1-1.module+el8.10.0+90960+1362bdc4
conmon
2.1.10-1.module+el8.10.0+90960+1362bdc4
container-selinux
2.229.0-3.module+el8.10.0+90960+1362bdc4
containernetworking-plugins
1.4.0-8.module+el8.10.0+90960+1362bdc4
containers-common
1-82.0.1.module+el8.10.0+90960+1362bdc4
crit
3.18-5.module+el8.10.0+90960+1362bdc4
criu
3.18-5.module+el8.10.0+90960+1362bdc4
criu-devel
3.18-5.module+el8.10.0+90960+1362bdc4
criu-libs
3.18-5.module+el8.10.0+90960+1362bdc4
crun
1.14.3-2.module+el8.10.0+90960+1362bdc4
fuse-overlayfs
1.13-1.module+el8.10.0+90960+1362bdc4
libslirp
4.4.0-2.module+el8.10.0+90960+1362bdc4
libslirp-devel
4.4.0-2.module+el8.10.0+90960+1362bdc4
netavark
1.10.3-1.module+el8.10.0+90960+1362bdc4
oci-seccomp-bpf-hook
1.2.10-1.module+el8.10.0+90960+1362bdc4
podman
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-catatonit
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-docker
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-gvproxy
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-plugins
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-remote
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-tests
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
python3-criu
3.18-5.module+el8.10.0+90960+1362bdc4
python3-podman
4.9.0-3.module+el8.10.0+90960+1362bdc4
runc
1.2.9-4.module+el8.10.0+90960+1362bdc4
skopeo
1.14.6-2.module+el8.10.0+90960+1362bdc4
skopeo-tests
1.14.6-2.module+el8.10.0+90960+1362bdc4
slirp4netns
1.2.3-1.module+el8.10.0+90960+1362bdc4
udica
0.2.6-21.module+el8.10.0+90960+1362bdc4
Oracle Linux x86_64
Module container-tools:ol8 is enabled
aardvark-dns
1.10.1-2.module+el8.10.0+90960+1362bdc4
buildah
1.33.14-4.module+el8.10.0+90960+1362bdc4
buildah-tests
1.33.14-4.module+el8.10.0+90960+1362bdc4
cockpit-podman
84.1-1.module+el8.10.0+90960+1362bdc4
conmon
2.1.10-1.module+el8.10.0+90960+1362bdc4
container-selinux
2.229.0-3.module+el8.10.0+90960+1362bdc4
containernetworking-plugins
1.4.0-8.module+el8.10.0+90960+1362bdc4
containers-common
1-82.0.1.module+el8.10.0+90960+1362bdc4
crit
3.18-5.module+el8.10.0+90960+1362bdc4
criu
3.18-5.module+el8.10.0+90960+1362bdc4
criu-devel
3.18-5.module+el8.10.0+90960+1362bdc4
criu-libs
3.18-5.module+el8.10.0+90960+1362bdc4
crun
1.14.3-2.module+el8.10.0+90960+1362bdc4
fuse-overlayfs
1.13-1.module+el8.10.0+90960+1362bdc4
libslirp
4.4.0-2.module+el8.10.0+90960+1362bdc4
libslirp-devel
4.4.0-2.module+el8.10.0+90960+1362bdc4
netavark
1.10.3-1.module+el8.10.0+90960+1362bdc4
oci-seccomp-bpf-hook
1.2.10-1.module+el8.10.0+90960+1362bdc4
podman
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-catatonit
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-docker
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-gvproxy
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-plugins
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-remote
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
podman-tests
4.9.4-34.0.1.module+el8.10.0+90960+1362bdc4
python3-criu
3.18-5.module+el8.10.0+90960+1362bdc4
python3-podman
4.9.0-3.module+el8.10.0+90960+1362bdc4
runc
1.2.9-4.module+el8.10.0+90960+1362bdc4
skopeo
1.14.6-2.module+el8.10.0+90960+1362bdc4
skopeo-tests
1.14.6-2.module+el8.10.0+90960+1362bdc4
slirp4netns
1.2.3-1.module+el8.10.0+90960+1362bdc4
udica
0.2.6-21.module+el8.10.0+90960+1362bdc4
Связанные CVE
Связанные уязвимости
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.