runc-1.4.2-3.el9_8

エラータID: AXSA:2026-1907:04

Release date: 
Thursday, September 24, 2026 - 20:17
Subject: 
runc-1.4.2-3.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.

Security Fix(es):

* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. runc-1.4.2-3.el9_8.src.rpm
    MD5: 2fdbb7d2db0c564c2b92561499036463
    SHA-256: 26c0b0019ba43242985f2b9ceb2b44d2886174d56168443c9a7f2ac7c6ce4baf
    Size: 2.81 MB

Asianux Server 9 for x86_64
  1. runc-1.4.2-3.el9_8.x86_64.rpm
    MD5: 1f401b0a01546daba93680a03ce2047b
    SHA-256: fb14b98011126a31ee00bca462d7ba9a68c9fa446453b459c1ad0b3cb183c354
    Size: 3.65 MB