skopeo-1.22.2-8.el9_8

エラータID: AXSA:2026-1913:05

Release date: 
Friday, September 25, 2026 - 14:11
Subject: 
skopeo-1.22.2-8.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Command line utility to inspect images and repositories directly on Docker registries without the need to pull them.

Security Fix(es):

* skopeo: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* skopeo: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* skopeo: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* skopeo: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* skopeo: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-11395
A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.
CVE-2026-33818
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
CVE-2026-56853
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
CVE-2026-56858
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
CVE-2026-56862
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. skopeo-1.22.2-8.el9_8.src.rpm
    MD5: 910a9edbfad11f674bcc089ad6e5aef7
    SHA-256: da56b28f5410b9ab7348b3cfa7ca4fd9ea6ec9738e8aa85dffd2ca1ec89555c0
    Size: 9.72 MB

Asianux Server 9 for x86_64
  1. skopeo-1.22.2-8.el9_8.x86_64.rpm
    MD5: 1120f252924d8c58421fa82d4e12162f
    SHA-256: c6bcafeea0c255b414502909dc1993288c0a89d9eb484b8a5f8fef3f58e06aab
    Size: 8.21 MB
  2. skopeo-tests-1.22.2-8.el9_8.x86_64.rpm
    MD5: bc3b5de68d671c4ab34d346b6a33aa9c
    SHA-256: c336fd2b7654c0ec6908573a7802012f5cdcd7a0c577a83ea14209593aef59be
    Size: 768.28 kB