runc-1.4.2-2.el9_8
エラータID: AXSA:2026-1427:03
リリース日:
2026/08/04 Tuesday - 10:10
題名:
runc-1.4.2-2.el9_8
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Golang の net/url.Parse ライブラリ関数には、無効な URL を
受け入れてしまう問題があるため、リモートの攻撃者により、サービス
拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-25679)
- Golang の crypto/x509 ライブラリおよび crypto/tls ライブラリ
には、証明書チェーンの構築処理においてリソースの制限を実施して
いない問題があるため、リモートの攻撃者により、サービス拒否攻撃
(リソース枯渇) を可能とする脆弱性が存在します。(CVE-2026-32280)
- Golang の crypto/x509 には、ループ内で過剰にプラットフォーム
リソースを消費してしまう問題があるため、リモートの攻撃者により、
サービス拒否攻撃 (DoS) サービス拒否攻撃を可能とする脆弱性が存在
します。(CVE-2026-32281)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
追加情報:
N/A
ダウンロード:
SRPMS
- runc-1.4.2-2.el9_8.src.rpm
MD5: b9844b527df47050511b1bcee802c80a
SHA-256: 0ed2f7459c2708ca2c24d2b551798a4807eb68a87a2ea83d366f94c7381697fd
Size: 2.81 MB
Asianux Server 9 for x86_64
- runc-1.4.2-2.el9_8.x86_64.rpm
MD5: d077e52cf6b8e0ca777466e67726fd34
SHA-256: cb66bcc6c14d9283a689f3b8a8ebceebaa9ba1e6ffd81b1843c070234a6d89e7
Size: 3.66 MB