git-lfs-3.7.1-4.el9_8.1
エラータID: AXSA:2026-1441:10
リリース日:
2026/08/04 Tuesday - 16:15
題名:
git-lfs-3.7.1-4.el9_8.1
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Golang の idna コンポーネントには、リモートの攻撃者により巧妙
に細工された Punycode ラベルを介して、特権昇格を可能とする脆弱性
が存在します。(CVE-2026-39821)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
追加情報:
N/A
ダウンロード:
SRPMS
- git-lfs-3.7.1-4.el9_8.1.src.rpm
MD5: 8f8b9f4645ab26e02959b941e23fd62e
SHA-256: 2f03d1d2c9e8f57870a285af34b884438dc4aa9dc5833835b80c98a7db6884f5
Size: 3.88 MB
Asianux Server 9 for x86_64
- git-lfs-3.7.1-4.el9_8.1.x86_64.rpm
MD5: 6395ad5bbb9a2046fa32a6d0a5f8e0ec
SHA-256: 255baa1451b33b1e9fb445a8f237219ea2b7e7f923a861af0d456c735fd1597a
Size: 4.79 MB