buildah-1.43.1-2.el9_8

エラータID: AXSA:2026-1405:05

Release date: 
Friday, July 31, 2026 - 18:11
Subject: 
buildah-1.43.1-2.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
CVE-2026-39829
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.
CVE-2026-39830
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. buildah-1.43.1-2.el9_8.src.rpm
    MD5: f73c8de23742f09504f7f8afef761588
    SHA-256: bdeea7ddd0fe3c8f10cc3bba8b4b7acee0c3a839d8025e144ba73ce5fbbc9d9b
    Size: 11.17 MB

Asianux Server 9 for x86_64
  1. buildah-1.43.1-2.el9_8.x86_64.rpm
    MD5: 30f81a564b51ca65a0f552b62a2025d1
    SHA-256: 67dd95f98398b3bfac13b1be62d5bc6ff99db877dd0a6c2a8cc25f7e077a74a0
    Size: 10.62 MB
  2. buildah-tests-1.43.1-2.el9_8.x86_64.rpm
    MD5: 87b7d88cee48b9a6d85b6034e2f0f8cc
    SHA-256: 559d4eacce67ce2a64cbf4a15adb2ecf9e75f84533d85773dbfef6bc779371b9
    Size: 30.75 MB