Вернуться к предупреждениям о безопасности

Container-Tools:rhel8 Security Update — AlmaLinux 8 (ALSA-2026:38504)

This is a security release for AlmaLinux 8. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.

High
AlmaLinux 8

Команды исправления

EL8+ (AlmaLinux/CloudLinux/Rocky)

sudo dnf update

Что это значит по лицензии SharedLicense

Your SharedLicense license itself is not affected — this is a change in AlmaLinux 8 software, not in licensing. Update the product through its standard update channel. Licenses keep working through updates; nothing needs re-issuing or re-activating.

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of …

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.  

Security Fix(es):  

  * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  * golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
  * podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Проверьте систему на уязвимости

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Проверьте свою систему