buildah-1.41.8-3.el9_7
エラータID: AXSA:2026-524:03
リリース日:
2026/05/04 Monday - 10:14
題名:
buildah-1.41.8-3.el9_7
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Go 言語向けの JOSE の key_wrap.go の cipher.KeyUnwrap() 関数
には、バッファサイズの算出処理の不備に起因してサイズがゼロもしく
はマイナス値のメモリ領域の割り当てを試行してしまう問題があるため、
リモートの攻撃者により、alg フィールドにおいてキーラッピング
アルゴリズムが指定され、かつ encrypted_key フィールドが空となる
ように巧妙に細工された JWE オブジェクトの入力を介して、サービス
拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-34986)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-34986
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.
追加情報:
N/A
ダウンロード:
SRPMS
- buildah-1.41.8-3.el9_7.src.rpm
MD5: 98c947bb35e3fabd361bf5babe089206
SHA-256: 3236026ffe38b42d4ae4641ce25484c1df70943bf1929f06cd32ad4f4d891ea7
Size: 11.35 MB
Asianux Server 9 for x86_64
- buildah-1.41.8-3.el9_7.x86_64.rpm
MD5: c8203f5497ad28821c049e245f420b9a
SHA-256: 1d10a38d550f840fafb7d2592fd04010de06d9642e3a08034bf3e79665641937
Size: 10.40 MB - buildah-tests-1.41.8-3.el9_7.x86_64.rpm
MD5: 08c2c76c5ce792539dc4648ef30a22b2
SHA-256: 5ed1b412daab9143777ac5cd832f89de0f7a1d903a3946e3492c4baaa15b2f7d
Size: 29.18 MB