Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:35833

Опубликовано: 06 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: container-tools:rhel8 security update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)

  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)

  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)

  • golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)

  • golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
aardvark-dnsx86_642.module+el8.10.0+40133+32c21f88aardvark-dns-1.10.1-2.module+el8.10.0+40133+32c21f88.x86_64.rpm
cockpit-podmannoarch1.module+el8.10.0+40133+32c21f88cockpit-podman-84.1-1.module+el8.10.0+40133+32c21f88.noarch.rpm
buildahx86_644.module+el8.10.0+40250+03a44a60buildah-1.33.14-4.module+el8.10.0+40250+03a44a60.x86_64.rpm
buildah-testsx86_644.module+el8.10.0+40250+03a44a60buildah-tests-1.33.14-4.module+el8.10.0+40250+03a44a60.x86_64.rpm
conmonx86_641.module+el8.10.0+40133+32c21f88conmon-2.1.10-1.module+el8.10.0+40133+32c21f88.x86_64.rpm
containernetworking-pluginsx86_648.module+el8.10.0+40133+32c21f88containernetworking-plugins-1.4.0-8.module+el8.10.0+40133+32c21f88.x86_64.rpm
containers-commonx86_6482.module+el8.10.0+40133+32c21f88containers-common-1-82.module+el8.10.0+40133+32c21f88.x86_64.rpm
critx86_645.module+el8.10.0+40133+32c21f88crit-3.18-5.module+el8.10.0+40133+32c21f88.x86_64.rpm
criux86_645.module+el8.10.0+40133+32c21f88criu-3.18-5.module+el8.10.0+40133+32c21f88.x86_64.rpm
criu-develx86_645.module+el8.10.0+40133+32c21f88criu-devel-3.18-5.module+el8.10.0+40133+32c21f88.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
24 дня назад

ELSA-2026-35833: container-tools:ol8 security update (IMPORTANT)

suse-cvrf
около 1 месяца назад

Security update for podman

suse-cvrf
около 1 месяца назад

Security update for podman

suse-cvrf
около 1 месяца назад

Security update for google-osconfig-agent

suse-cvrf
около 1 месяца назад

Security update for apptainer