skopeo-1.22.2-6.el9_8
エラータID: AXSA:2026-1395:03
リリース日:
2026/07/31 Friday - 11:00
題名:
skopeo-1.22.2-6.el9_8
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Golang の crypto/x509 ライブラリおよび crypto/tls ライブラリ
には、証明書チェーンの構築処理においてリソースの制限を実施して
いない問題があるため、リモートの攻撃者により、サービス拒否攻撃
(リソース枯渇) を可能とする脆弱性が存在します。(CVE-2026-32280)
- Golang の crypto/x509 には、ループ内で過剰にプラットフォーム
リソースを消費してしまう問題があるため、リモートの攻撃者により、
サービス拒否攻撃 (DoS) サービス拒否攻撃を可能とする脆弱性が存在
します。(CVE-2026-32281)
- Golang の crypto/tls パッケージには、TLS 1.3 のハンドシェイク後
の処理においてデッドロックに至る問題があるため、リモートの攻撃者
により、サービス拒否攻撃を可能とする脆弱性が存在します。
(CVE-2026-32283)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
追加情報:
N/A
ダウンロード:
SRPMS
- skopeo-1.22.2-6.el9_8.src.rpm
MD5: 56cd54084e1feec5012c8bfd83f9ca75
SHA-256: 519e9cdb581c0d42775ff96bd0b346b7d3a8617e5600c571d9ad6afe862c0fc7
Size: 9.72 MB
Asianux Server 9 for x86_64
- skopeo-1.22.2-6.el9_8.x86_64.rpm
MD5: 70f1a4e753fc27765305e9faac282be7
SHA-256: 144330053c118a6c46c842d2e5b03ce6670c0ad9389043f2a9fead20ad59b525
Size: 8.21 MB - skopeo-tests-1.22.2-6.el9_8.x86_64.rpm
MD5: 4a5f803cc8de9c51418227d229cb42c9
SHA-256: a2f5a505c54e916e0f69daa91b14a5a0654e1b6e1783c1f4b3687d81c0576b7b
Size: 767.88 kB