skopeo-1.22.2-6.el9_8
エラータID: AXSA:2026-1395:03
The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.
Security Fix(es):
* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
Update packages.
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
N/A
SRPMS
- skopeo-1.22.2-6.el9_8.src.rpm
MD5: 56cd54084e1feec5012c8bfd83f9ca75
SHA-256: 519e9cdb581c0d42775ff96bd0b346b7d3a8617e5600c571d9ad6afe862c0fc7
Size: 9.72 MB
Asianux Server 9 for x86_64
- skopeo-1.22.2-6.el9_8.x86_64.rpm
MD5: 70f1a4e753fc27765305e9faac282be7
SHA-256: 144330053c118a6c46c842d2e5b03ce6670c0ad9389043f2a9fead20ad59b525
Size: 8.21 MB - skopeo-tests-1.22.2-6.el9_8.x86_64.rpm
MD5: 4a5f803cc8de9c51418227d229cb42c9
SHA-256: a2f5a505c54e916e0f69daa91b14a5a0654e1b6e1783c1f4b3687d81c0576b7b
Size: 767.88 kB