Volver a los avisos de seguridad

Container-Tools:rhel8 Security Update — AlmaLinux 8 (ALSA-2026:38504)

This is a security release for AlmaLinux 8. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.

High
AlmaLinux 8

Comandos de corrección

EL8+ (AlmaLinux/CloudLinux/Rocky)

sudo dnf update

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a change in AlmaLinux 8 software, not in licensing. Update the product through its standard update channel. Licenses keep working through updates; nothing needs re-issuing or re-activating.

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of …

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.  

Security Fix(es):  

  * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  * golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
  * podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema