Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:49944: Important: container-tools:rhel8 security, bug fix, and enhancement update

  • What: Security, bug fix, and enhancement update for container-tools:rhel8
  • Impact: Red Hat Enterprise Linux 8.8 systems affected
Read Full Article →

Red Hat Product Errata RHSA-2026:49944 - Security Advisory Issued: 2026-08-04 Updated: 2026-08-04 RHSA-2026:49944 - Security Advisory Overview Updated Packages Synopsis Important: container-tools:rhel8 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728) golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) Bug Fix(es) and Enhancement(s): [RHEL 8.8] Buildah specfile missing dumpspec test binary (JIRA:RHEL-170411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate BZ - 2434431 - CVE-2025-61728 golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url BZ - 2455470 - CVE-2026-34986 github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building BZ - 2480681 - CVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters BZ - 2480684 - CVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses BZ - 2480685 - CVE-2026-39832 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions BZ - 2480688 - CVE-2026-42508 golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVEs CVE-2025-61726 CVE-2025-61728 CVE-2025-61729 CVE-2025-68121 CVE-2026-25679 CVE-2026-32280 CVE-2026-32281 CVE-2026-32283 CVE-2026-34986 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-42508 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM aardvark-dns-1.5.0-2.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 960ad6009556798fb98fc2eb251bd1cf8d278d498f483c9007f54ec4744d2a8f buildah-1.29.8-1.module+el8.8.0+24545+b713e821.src.rpm SHA-256: eeb848eb2e2e9d8430ac0628ca036ac6588e366e0cf2c8ef14842e37c8c22d39 cockpit-podman-63.1-1.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 3635ab2d3c9a12f295526f6eb7fc6af776d1c8b5b989f1f6f488e18999804930 conmon-2.1.6-1.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 444aebe8a782f8977ac975f36be18b68874cfb91443cc466be80b54a110eba13 container-selinux-2.229.0-1.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 89ba83577aca39820145d9d02f3d80b3b7a26b233af54767d5c7903c36427113 containernetworking-plugins-1.2.0-3.module+el8.8.0+24525+a924b82f.1.src.rpm SHA-256: 955771f7969a949fc9f50b9a6243a0d6886924ac1992d456ad3e5669d7fce89d containers-common-1-67.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 5d9c50cb3837a9ca97ebab791325319d513b5e09060605ae15f134f3b7b89dc7 criu-3.15-4.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 1f9321c8075cd7f4347c11cee790088e9f82168afe2361e877eed18c5cfda0da crun-1.14.3-1.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: c4b66c3a4ffffb91d42960539ecfb0bb103ed97e1fbcf05cffd5d2256b8bf6df fuse-overlayfs-1.11-1.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 9e172f8cc6725e11fb9c362b8a271211083056e0871e197f3345600b2d3f0b59 libslirp-4.4.0-1.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 5cf18c72440e24367131332805cf556849939fffe111cd8e8af497483a95f276 netavark-1.5.1-3.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 2bc1cfc61114918345c6b68c3443f11817def5711f6c35d6579c4e70f7fa3aaf oci-seccomp-bpf-hook-1.2.10-1.module+el8.8.0+24130+2fde7a57.src.rpm SHA-256: 219cab8cffcc73af9058d48787977660f70aeedc47fe4773b36c90d1cc982b56 podman-4.4.1-27.module+el8.8.0+24545+b713e821.8.src.rpm SHA-256: f17c0630307ec5cd836fbc0f874c7786017887a767d6b90df6fc0baa048e1792 python-podman-4.4.1-1.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 92df420492a1e298f86887b3c5ed2afaebbb3ed6889bd579c5d28aee562f410e runc-1.2.9-1.module+el8.8.0+24525+a924b82f.1.src.rpm SHA-256: 7618b7ab1184b12c99608a7e7b1adfeacbadcaede5229d095bfcdc94fd20ff97 skopeo-1.11.6-1.module+el8.8.0+24525+a924b82f.src.rpm SHA-256: a4b75aecb7a264d227f62c11ed6ccad6a61f3f086a8fb46c5a2a41e7dfb5d965 slirp4netns-1.2.0-3.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 00e54c7901cfec2376466c72621bea8127c3659210e86bfa261cfba70f8bc109 toolbox-0.0.99.3-7.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 5e89d16b566675df35ff3bb869969ad39a5f9777dbcd43ff1117735c78bb7370 udica-0.2.6-20.module+el8.8.0+23884+2031fc78.src.rpm SHA-256: 99fa8e1040e627ef22d45c9ffd6eab1547c4305bef2853aa507925861e560222 x86_64 cockpit-podman-63.1-1.module+el8.8.0+23884+2031fc78.noarch.rpm SHA-256: 3ae0eb03cdabb877cceabe1233a7ebc477bc64efac680318b6ef48e2162986f2 container-selinux-2.229.0-1.module+el8.8.0+23884+2031fc78.noarch.rpm SHA-256: 2f0fbb3d0025fb3677ed5f56b3db72e8837d632d6a813be2f9f77dd34e6d1613 podman-docker-4.4.1-27.module+el8.8.0+24545+b713e821.8.noarch.rpm SHA-256: fc46ddc2f36c1d774098ebbe086d47503d5528b0aa28ce24b2729179b5f4a7fb python3-podman-4.4.1-1.module+el8.8.0+23884+2031fc78.noarch.rpm SHA-256: e5f1e4e5ecdb3fc6d94c5ad2a0258045b82e4f1b71e607bfc6f90e8b3b6a7d75 udica-0.2.6-20.module+el8.8.0+23884+2031fc78.noarch.rpm SHA-256: 9afde4b04830aeecf0bed567d354a962482bf653d9b9edeffb8544e5ed162677 aardvark-dns-1.5.0-2.module+el8.8.0+23884+2031fc78.x86_64.rpm SHA-256: 39e44b2d585fb4c7208de1aa0c79b6872f76c56dd5c08948b45c978eb5b084e7 buildah-1.29.8-1.module+el8.8.0+24545+b713e821.x86_64.rpm SHA-256: c35b0db8d76971d23c489ab41a1a70279c1b800ea3bed04179a43f26f82aded2 buildah-debuginfo-1.29.8-1.module+el8.8.0+24545+b713e821.x86_64.rpm SHA-256: bd096b341443a91c4784aad09d3ebc884e23280b1f67a505df4ce7db5eb5409f buildah-debugsource-1.29.8-1.module+el8.8.0+24545+b713e821.x86_64.rpm SHA-256: 7e6ca7b68589cbcc1ddfa5f5dae97da70e9b4faf12482cf30f1ad544b91bed3f buildah-tests-1.29.8-1.module+el8.8.0+24545+b713e821.x86_64.rpm SHA-256: d06781560d4f9455c0220395ff993eff7557fd588e1294ad8df61f4cd1fe62e3 buildah-tests-debuginfo-1.29.8-1.module+el8.8.0+24545+b713e821.x86_64.rpm SHA-256: 8691bf5f03b0ab4ab7796095126baf73e9a06a655e8c012a12416bdb762573e8 cockpit-podman-63.1-1.module+el8.8.0+23884+2031fc78.noarch.rpm SHA-256: 3ae0eb03cdabb877cceabe1233a7ebc477bc64efac680318b6ef48e2162986f2 conmon-2.1.6-1.module+el8.8.0+23884+2031fc78.x86_64.rpm SHA-256: bf43860594b1e9c39f56ad726acbbf99503daffd950d868a8c24466c254de568 conmon-debuginfo-2.1.6-1.module+el8.8.0+23884+2031fc78.x86_64.rpm SHA-256: 34

Share this article