containernetworking-plugins-1.9.0-3.el9_8
エラータID: AXSA:2026-1426:03
リリース日:
2026/08/04 Tuesday - 09:42
題名:
containernetworking-plugins-1.9.0-3.el9_8
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Golang の net/url.Parse ライブラリ関数には、無効な URL を
受け入れてしまう問題があるため、リモートの攻撃者により、サービス
拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-25679)
- Golang の crypto/x509 ライブラリおよび crypto/tls ライブラリ
には、証明書チェーンの構築処理においてリソースの制限を実施して
いない問題があるため、リモートの攻撃者により、サービス拒否攻撃
(リソース枯渇) を可能とする脆弱性が存在します。(CVE-2026-32280)
- Golang の crypto/x509 には、ループ内で過剰にプラットフォーム
リソースを消費してしまう問題があるため、リモートの攻撃者により、
サービス拒否攻撃 (DoS) サービス拒否攻撃を可能とする脆弱性が存在
します。(CVE-2026-32281)
- Golang の crypto/tls パッケージには、TLS 1.3 のハンドシェイク後
の処理においてデッドロックに至る問題があるため、リモートの攻撃者
により、サービス拒否攻撃を可能とする脆弱性が存在します。
(CVE-2026-32283)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
追加情報:
N/A
ダウンロード:
SRPMS
- containernetworking-plugins-1.9.0-3.el9_8.src.rpm
MD5: 84b95af1c49792e07faf146d71c4cf3d
SHA-256: 9b4f43424a5df78039dcfbd7c5110f31d88a2c43c454d14777fa1920b88e65f4
Size: 3.71 MB
Asianux Server 9 for x86_64
- containernetworking-plugins-1.9.0-3.el9_8.x86_64.rpm
MD5: 7bd21a2a8468f878f42485c608b8bb51
SHA-256: 4e9c91714ca77651d4f161bdf3aaa729d49e1fc85999763969bb3e7c3d5918ce
Size: 12.68 MB