opentelemetry-collector-0.152.1-1.el9_8
エラータID: AXSA:2026-1458:04
以下項目について対処しました。
[Security Fix]
- Golang には、クロスサイトスクリプティング攻撃を許容してしまう
問題があるため、リモートの攻撃者により、巧妙に細工された HTML
ファイルを介して、任意のコードの実行を可能とする脆弱性が存在します。
(CVE-2026-25681)
- Golang の crypto/x509 パッケージには、リモートの攻撃者により、
巧妙に細工された X.509 証明書ファイルを介して、サービス拒否攻撃
を可能とする脆弱性が存在します。(CVE-2026-27145)
- Golang の net パッケージには、メモリ領域の二重解放の問題が
あるため、リモートの攻撃者により、巧妙に細工された CNAME 応答を
介して、サービス拒否攻撃 (クラッシュの発生) を可能とする脆弱性が
存在します。(CVE-2026-33811)
- Golang の idna コンポーネントには、リモートの攻撃者により巧妙
に細工された Punycode ラベルを介して、特権昇格を可能とする脆弱性
が存在します。(CVE-2026-39821)
- Prometheus には、機密情報を誤って平文で処理してしまう問題が
あるため、リモートの攻撃者により、情報の漏洩を可能とする脆弱性が
存在します。(CVE-2026-42151)
- Prometheus には、リソースの制限を実施していない問題があるため、
リモートの攻撃者により、巧妙に細工された Snappy 圧縮ペイロードを
介して、サービス拒否攻撃 (DoS) を可能とする脆弱性が存在します。
(CVE-2026-42154)
パッケージをアップデートしてください。
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
N/A
SRPMS
- opentelemetry-collector-0.152.1-1.el9_8.src.rpm
MD5: d6031b78cc6bbe06e2ea036dfde48326
SHA-256: 2833994cd5af49d40e69b5c3f14bb018faac6d7a2d9fb467bde99732d8347bb3
Size: 27.44 MB
Asianux Server 9 for x86_64
- opentelemetry-collector-0.152.1-1.el9_8.x86_64.rpm
MD5: badb81099008cfb30c916b4680072305
SHA-256: 4a6eecb10f44f9e2ca4fcc00a8f2691d3aaf8fd93cb239161006bf516b3ffe4b
Size: 40.13 MB