runc-1.4.2-2.el9_8
エラータID: AXSA:2026-1427:03
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.
Security Fix(es):
* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Update packages.
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
N/A
SRPMS
- runc-1.4.2-2.el9_8.src.rpm
MD5: b9844b527df47050511b1bcee802c80a
SHA-256: 0ed2f7459c2708ca2c24d2b551798a4807eb68a87a2ea83d366f94c7381697fd
Size: 2.81 MB
Asianux Server 9 for x86_64
- runc-1.4.2-2.el9_8.x86_64.rpm
MD5: d077e52cf6b8e0ca777466e67726fd34
SHA-256: cb66bcc6c14d9283a689f3b8a8ebceebaa9ba1e6ffd81b1843c070234a6d89e7
Size: 3.66 MB