Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:38504

Опубликовано: 13 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: container-tools:rhel8 security update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)

  • golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)

  • podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
buildahaarch644.module+el8.10.0+40250+03a44a60buildah-1.33.14-4.module+el8.10.0+40250+03a44a60.aarch64.rpm
buildah-testsaarch644.module+el8.10.0+40250+03a44a60buildah-tests-1.33.14-4.module+el8.10.0+40250+03a44a60.aarch64.rpm
podmanaarch6434.module+el8.10.0+40250+03a44a60podman-4.9.4-34.module+el8.10.0+40250+03a44a60.aarch64.rpm
podman-catatonitaarch6434.module+el8.10.0+40250+03a44a60podman-catatonit-4.9.4-34.module+el8.10.0+40250+03a44a60.aarch64.rpm
podman-dockernoarch34.module+el8.10.0+40250+03a44a60podman-docker-4.9.4-34.module+el8.10.0+40250+03a44a60.noarch.rpm
podman-gvproxyaarch6434.module+el8.10.0+40250+03a44a60podman-gvproxy-4.9.4-34.module+el8.10.0+40250+03a44a60.aarch64.rpm
podman-pluginsaarch6434.module+el8.10.0+40250+03a44a60podman-plugins-4.9.4-34.module+el8.10.0+40250+03a44a60.aarch64.rpm
podman-remoteaarch6434.module+el8.10.0+40250+03a44a60podman-remote-4.9.4-34.module+el8.10.0+40250+03a44a60.aarch64.rpm
podman-testsaarch6434.module+el8.10.0+40250+03a44a60podman-tests-4.9.4-34.module+el8.10.0+40250+03a44a60.aarch64.rpm
aardvark-dnsaarch642.module+el8.10.0+1896+b18fa106aardvark-dns-1.10.1-2.module+el8.10.0+1896+b18fa106.aarch64.rpm

Показывать по

Связанные уязвимости

oracle-oval
2 месяца назад

ELSA-2026-38504: container-tools:ol8 security update (IMPORTANT)

CVSS3: 7.5
ubuntu
4 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

CVSS3: 7.5
redhat
4 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

CVSS3: 7.5
nvd
4 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

msrc
4 месяца назад

Crash when handling long CNAME response in net