podman-5.8.2-3.el9_8
エラータID: AXSA:2026-1345:06
リリース日:
2026/07/27 Monday - 18:39
題名:
podman-5.8.2-3.el9_8
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Golang の crypto/x509 ライブラリおよび crypto/tls ライブラリ
には、証明書チェーンの構築処理においてリソースの制限を実施して
いない問題があるため、リモートの攻撃者により、サービス拒否攻撃
(リソース枯渇) を可能とする脆弱性が存在します。(CVE-2026-32280)
- Golang の crypto/x509 には、ループ内で過剰にプラットフォーム
リソースを消費してしまう問題があるため、リモートの攻撃者により、
サービス拒否攻撃 (DoS) サービス拒否攻撃を可能とする脆弱性が存在
します。(CVE-2026-32281)
- Golang の crypto/tls パッケージには、TLS 1.3 のハンドシェイク
後の処理においてデッドロックに至る問題があるため、リモートの攻撃者
により、サービス拒否攻撃を可能とする脆弱性が存在します。
(CVE-2026-32283)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
追加情報:
N/A
ダウンロード:
SRPMS
- podman-5.8.2-3.el9_8.src.rpm
MD5: df47825716cd770ca01983575e8600aa
SHA-256: 0c7f89c6035b2758ea9ed1163728038778e22d490312bfd5609552a2ea17de40
Size: 22.34 MB
Asianux Server 9 for x86_64
- podman-5.8.2-3.el9_8.x86_64.rpm
MD5: f06fcce1336388c726fb77481f28d83c
SHA-256: 3a38dbeb2b693e1b937383e9a8853a92e5b97a01d86091bc47a852b777e9d525
Size: 16.47 MB - podman-docker-5.8.2-3.el9_8.noarch.rpm
MD5: 6fae97c2ddaba495a7da411dd47afd22
SHA-256: 010c907a3c21108d4e747af42b3e621cb7916c0208fc778d0a3edafef783d300
Size: 106.71 kB - podman-plugins-5.8.2-3.el9_8.x86_64.rpm
MD5: 53c1e0b0d18f3e4dca5575ee8a0cbce7
SHA-256: 67464e6cc0562a871b4bd874607ca0ee3a6ab60b1a1d2a4cf7bd123043c10a72
Size: 1.49 MB - podman-remote-5.8.2-3.el9_8.x86_64.rpm
MD5: b3a6ee1517846766a0ab1453e8473fbb
SHA-256: 03d98bbbdec8a0b5b713a80f68d59998c396667cc28b370d6686eca224b8e989
Size: 10.10 MB - podman-tests-5.8.2-3.el9_8.x86_64.rpm
MD5: dbbddc0ce20981cd4a03f9deaf608015
SHA-256: d32f9f6bffc8a5187d37a6181b7004acca0163f3460401bab72ab70e4370ca85
Size: 11.72 MB