Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:33722

Опубликовано: 01 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: container-tools:rhel8 security, bug fix, and enhancement update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)

  • github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)

  • crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)

  • crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)

  • crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)

Bug Fix(es) and Enhancement(s):

  • user_u SELinux user can't run podman containers as rootless (JIRA:Rocky Linux-135342)

  • podman does not clean up all files and leaves orphaned files consuming disk space [rhel-8.10.z] (JIRA:Rocky Linux-173978)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
container-selinuxnoarch3.module+el8.10.0+40223+e940a224container-selinux-2.229.0-3.module+el8.10.0+40223+e940a224.noarch.rpm
podmanx86_6431.module+el8.10.0+40223+e940a224podman-4.9.4-31.module+el8.10.0+40223+e940a224.x86_64.rpm
podman-catatonitx86_6431.module+el8.10.0+40223+e940a224podman-catatonit-4.9.4-31.module+el8.10.0+40223+e940a224.x86_64.rpm
podman-dockernoarch31.module+el8.10.0+40223+e940a224podman-docker-4.9.4-31.module+el8.10.0+40223+e940a224.noarch.rpm
podman-gvproxyx86_6431.module+el8.10.0+40223+e940a224podman-gvproxy-4.9.4-31.module+el8.10.0+40223+e940a224.x86_64.rpm
podman-pluginsx86_6431.module+el8.10.0+40223+e940a224podman-plugins-4.9.4-31.module+el8.10.0+40223+e940a224.x86_64.rpm
podman-remotex86_6431.module+el8.10.0+40223+e940a224podman-remote-4.9.4-31.module+el8.10.0+40223+e940a224.x86_64.rpm
podman-testsx86_6431.module+el8.10.0+40223+e940a224podman-tests-4.9.4-31.module+el8.10.0+40223+e940a224.x86_64.rpm
skopeox86_642.module+el8.10.0+40223+e940a224skopeo-1.14.6-2.module+el8.10.0+40223+e940a224.x86_64.rpm
skopeo-testsx86_642.module+el8.10.0+40223+e940a224skopeo-tests-1.14.6-2.module+el8.10.0+40223+e940a224.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 1 месяца назад

ELSA-2026-33722: container-tools:ol8 security, bug fix, and enhancement update (IMPORTANT)

rocky
2 месяца назад

Important: opentelemetry-collector security update

rocky
2 месяца назад

Important: opentelemetry-collector security update

rocky
около 1 месяца назад

Important: containernetworking-plugins security update

rocky
около 1 месяца назад

Important: buildah security update