containernetworking-plugins-1.9.0-3.el9_8

エラータID: AXSA:2026-1426:03

Release date: 
Tuesday, August 4, 2026 - 09:42
Subject: 
containernetworking-plugins-1.9.0-3.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted.

Security Fix(es):

* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. containernetworking-plugins-1.9.0-3.el9_8.src.rpm
    MD5: 84b95af1c49792e07faf146d71c4cf3d
    SHA-256: 9b4f43424a5df78039dcfbd7c5110f31d88a2c43c454d14777fa1920b88e65f4
    Size: 3.71 MB

Asianux Server 9 for x86_64
  1. containernetworking-plugins-1.9.0-3.el9_8.x86_64.rpm
    MD5: 7bd21a2a8468f878f42485c608b8bb51
    SHA-256: 4e9c91714ca77651d4f161bdf3aaa729d49e1fc85999763969bb3e7c3d5918ce
    Size: 12.68 MB