skopeo-1.22.2-7.el9_8

エラータID: AXSA:2026-1477:04

Release date: 
Thursday, August 6, 2026 - 19:15
Subject: 
skopeo-1.22.2-7.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.

Security Fix(es):

* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
* crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. skopeo-1.22.2-7.el9_8.src.rpm
    MD5: 87d043f7a94840aed21a2172f1da8df6
    SHA-256: fb25f266fc0c4897bea51137de0998ec9068b32d2bc63b963bcd4546548c65f4
    Size: 9.72 MB

Asianux Server 9 for x86_64
  1. skopeo-1.22.2-7.el9_8.x86_64.rpm
    MD5: 0676e365b850249e1469370a2b735e89
    SHA-256: 2236ebe6eb293708f7f2f5633a2a0b0d6879bd40e4728f9c646c26c32fc4793d
    Size: 8.21 MB
  2. skopeo-tests-1.22.2-7.el9_8.x86_64.rpm
    MD5: b6d454ed5c78d15dfb34dd56537e6c2a
    SHA-256: ac49b48f240c778cdf98b2618f305e565f08ae0e6e19a6835d40f14240a83b14
    Size: 768.02 kB