runc-1.4.2-3.el9_8
エラータID: AXSA:2026-1907:04
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.
Security Fix(es):
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
Update packages.
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
N/A
SRPMS
- runc-1.4.2-3.el9_8.src.rpm
MD5: 2fdbb7d2db0c564c2b92561499036463
SHA-256: 26c0b0019ba43242985f2b9ceb2b44d2886174d56168443c9a7f2ac7c6ce4baf
Size: 2.81 MB
Asianux Server 9 for x86_64
- runc-1.4.2-3.el9_8.x86_64.rpm
MD5: 1f401b0a01546daba93680a03ce2047b
SHA-256: fb14b98011126a31ee00bca462d7ba9a68c9fa446453b459c1ad0b3cb183c354
Size: 3.65 MB